🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 441908dd27edc1effb4d1643d46d85b4750b8a660e75b7bbb4c81f2a143959d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 441908dd27edc1effb4d1643d46d85b4750b8a660e75b7bbb4c81f2a143959d6
SHA3-384 hash: 610a9162c3f4ab8d44727901511ecc4f2ecfdfca100ece9dbfd0fe824470b2cc9d386063f3918e2d8eac9dbed4be7135
SHA1 hash: a5cab9db413872bb74c5d252537edb521ca01185
MD5 hash: c9f23b6ee1ba97c753892e6c103521d6
humanhash: juliet-johnny-uncle-venus
File name:기획설문.doc
Download: download sample
File size:57'708 bytes
First seen:2021-03-27 13:25:57 UTC
Last seen:Never
File type:Word file doc
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 1536:TyUIlySV2WQFJODrkL/xcnwuFCQw9IiKl58RLZu40R+yip/26d:JIRTQTwYzqnwuFU9JeK4RUp/Td
TLSH 9543E1A96E4B1354EE37323D7DED67AFF630E5028C11D7AA694251E48DC215B0B0732E
Reporter vm001cn
Tags:doc macros

Intelligence


File Origin
# of uploads :
1
# of downloads :
192
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
기획설문.doc
Verdict:
No threats detected
Analysis date:
2021-03-27 13:23:59 UTC
Tags:
macros macros-on-open

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl.evad
Score:
56 / 100
Signature
Document contains an embedded VBA macro which may check the recent opened files (possible anti-VM)
Document contains an embedded VBA macro with suspicious strings
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Script-Macro.Trojan.Valyria
Status:
Malicious
First seen:
2021-03-27 02:12:00 UTC
AV detection:
7 of 28 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments