🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4612a9bca84a26562fb2b5da79528d4ff01362b18be9f2e95c12c8f59cc7dff1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 4612a9bca84a26562fb2b5da79528d4ff01362b18be9f2e95c12c8f59cc7dff1
SHA3-384 hash: a15ae95d44890449779354d1888fc0b4fcbd5ac8ee9af076b035f9eec785c8a4478f9edcd061efd923f74d2bae59da15
SHA1 hash: ba90f65e8564ac508ac2f3f05b9d5d3481732b99
MD5 hash: e0b1ab906df57682a707839103bfbbaf
humanhash: stairway-bulldog-floor-apart
File name:lnvoice-1597256897.pdf
Download: download sample
File size:52'618 bytes
First seen:2023-11-17 13:16:17 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:/6G55555555HRAIIHiy5nMxQ0H5H2eX8MPA:/6G555555551ICy5nMSfeo
TLSH T1C8337F30FBDBD7891B8B5A4D857F3C73574581D442E84173403B8C0AAAA8F3A4A976BC
Reporter JAMESWT_WT
Tags:bo0king-blogspot-com pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
483
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
88%
Tags:
scam
Verdict:
Malicious
Labled as:
PDF/TrojanDownloader.PowerShell
Label:
Malicious
Suspicious Score:
5.5/10
Score Malicious:
56%
Score Benign:
44%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1344113 Sample: lnvoice-1597256897.pdf Startdate: 17/11/2023 Architecture: WINDOWS Score: 48 36 Multi AV Scanner detection for submitted file 2->36 7 Acrobat.exe 55 2->7         started        9 chrome.exe 18 2->9         started        process3 dnsIp4 12 AcroCEF.exe 70 7->12         started        26 192.168.2.5 unknown unknown 9->26 28 239.255.255.250 unknown Reserved 9->28 14 chrome.exe 9->14         started        process5 dnsIp6 17 AcroCEF.exe 2 12->17         started        30 198.8.71.131 ROCKETFUELUS United States 14->30 32 18.172.170.109 MIT-GATEWAYSUS United States 14->32 34 93 other IPs or domains 14->34 process7 dnsIp8 20 162.159.61.3 CLOUDFLARENETUS United States 17->20 22 50.16.47.176 AMAZON-AESUS United States 17->22 24 104.117.232.185 AKAMAI-ASUS United States 17->24
Threat name:
Document-PDF.Trojan.Scam
Status:
Malicious
First seen:
2023-11-17 12:08:24 UTC
File Type:
Document
Extracted files:
7
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments