🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 631bb80597983633cf04ae82cf0aa9fa342bf85314d9f5bb09f9183abb5209e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 631bb80597983633cf04ae82cf0aa9fa342bf85314d9f5bb09f9183abb5209e8
SHA3-384 hash: 68b22a152d8c210dd96f5989078493d12453a517eacdfb3843ffdc89724f0d254f0961dd383065e110da6098d0bee833
SHA1 hash: dde39d5a6b13ea0fde332297dca15837d63b4ad8
MD5 hash: b8523485474d5ded915645f6f081279c
humanhash: south-kilo-earth-ten
File name:dhl_shp_delivery.ppsx
Download: download sample
File size:2'554'396 bytes
First seen:2022-01-31 13:15:03 UTC
Last seen:Never
File type:
MIME type:application/vnd.openxmlformats-officedocument.presentationml.presentation
ssdeep 49152:YruuTAx0TN3fonAkNaT73Si++2kDgtOGbAnuktRbpFsqatFwJH6Ez:yu0AiT7T7yLtOGknVRbTatuPz
TLSH T19BC5337CB34647D1F89F7A37E06749A36F01AD297AD1DB8C45BB270B00A4316285CACE
Reporter proxylife
Tags:CVE-2017-11882 Lokibot

Intelligence


File Origin
# of uploads :
1
# of downloads :
402
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Document-Office.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2022-01-31 13:15:17 UTC
File Type:
Document
Extracted files:
41
AV detection:
23 of 43 (53.49%)
Threat level:
  5/5
Malware family:
Lokibot
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments