🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a9a2c2926b7b8e388984d38cb9e259fb4060cccc2d291c7910be030ae5301a3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 4a9a2c2926b7b8e388984d38cb9e259fb4060cccc2d291c7910be030ae5301a3
SHA3-384 hash: 70dbd17e5d34d556f001eee4856ff5036cb37498469acebaf5537fe3c4f939fc9ed346af9426fc9e113c9c8a341bb2b9
SHA1 hash: 659f7a016c24752cb7e022a7a36e7435d9513bb7
MD5 hash: d3d64e1600d322dc7b3083c2406f1871
humanhash: carbon-mike-don-beryllium
File name:Proposed Scope Revisions.pdf
Download: download sample
File size:211'748 bytes
First seen:2024-08-15 19:46:07 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:8ZhYfPt/KcCzjYpV5ICPFIi1sUNfHJwcWQeuUtI+v52dVE5LXQtBqSmqWY96Pi3g:8Zqfhuj05ICtIDUV+QZUd52mXQDRd6r
TLSH T12E24F16C82A0296CF542CB70E617765E3F9DBC8951CD92CB1B60F2979130F0DA23A5DA
Reporter smica83
Tags:COLDWASTREL pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
346
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
Execution Generic Infostealer Network Stealth
Label:
Benign
Suspicious Score:
1.1/10
Score Malicious:
12%
Score Benign:
88%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
AI detected suspicious PDF
Antivirus detection for URL or domain
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1493529 Sample: Proposed Scope Revisions.pdf Startdate: 15/08/2024 Architecture: WINDOWS Score: 52 21 account.protondrive.online 2->21 35 Antivirus detection for URL or domain 2->35 37 AI detected suspicious PDF 2->37 8 chrome.exe 9 2->8         started        11 Acrobat.exe 18 62 2->11         started        signatures3 process4 dnsIp5 25 192.168.2.5, 443, 49531, 49593 unknown unknown 8->25 27 239.255.255.250 unknown Reserved 8->27 13 chrome.exe 8->13         started        16 AcroCEF.exe 107 11->16         started        process6 dnsIp7 29 www.google.com 142.250.185.164, 443, 49727, 49736 GOOGLEUS United States 13->29 31 google.com 13->31 33 account.protondrive.online 13->33 18 AcroCEF.exe 2 16->18         started        process8 dnsIp9 23 192.168.2.4 unknown unknown 18->23
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2023-03-23 21:05:01 UTC
File Type:
Document
Extracted files:
13
AV detection:
4 of 38 (10.53%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments