🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6bb20c1e83ad872f2e7f5a05ab90f0ffdd81a4e8ba5ed938e6f90e8efb12503e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6bb20c1e83ad872f2e7f5a05ab90f0ffdd81a4e8ba5ed938e6f90e8efb12503e
SHA3-384 hash: d49417c89b0e8f6e72a4c93dc996e63a2904eebf1e049eb801c96486b18b3b64d5f9dfe8894fd8d5edf1fc586e17eec1
SHA1 hash: dd1eb3e19e4006dfe9ff68562d2455c422409971
MD5 hash: 1790cae6b71f7e5bbbf85c841a0ccb22
humanhash: fourteen-edward-beryllium-blue
File name:002-NOTIFICACIONES FISCALES Y PROCESOS PENDIENTES_unique_JGNUVIH6_20241114_143752.pdf
Download: download sample
File size:90'809 bytes
First seen:2024-11-18 08:00:27 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:yGcCIRiBjc9bKyVboBKj7mw1UigU6aS4zJ6SlaPa7/GPGcFXRF2Oq:GCiiBjcfu4/mArjV6HaiPGcFXW
TLSH T13F93F134FF5A4C9CFE07C27965383C9A5AAE735A88C4748B01B98F63B0459994D236CF
Magika pdf
Reporter JAMESWT_WT
Tags:48D1F84EF enviodolares24-duckdns-org pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
297
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
3.5/10
Score Malicious:
35%
Score Benign:
65%
Result
Threat name:
n/a
Detection:
suspicious
Classification:
troj
Score:
22 / 100
Signature
Uses known network protocols on non-standard ports
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1557437 Sample: 002-NOTIFICACIONES FISCALES... Startdate: 18/11/2024 Architecture: WINDOWS Score: 22 20 x1.i.lencr.org 2->20 30 Uses known network protocols on non-standard ports 2->30 8 chrome.exe 9 2->8         started        11 Acrobat.exe 18 56 2->11         started        signatures3 process4 dnsIp5 22 192.168.2.8, 138, 443, 49706 unknown unknown 8->22 24 239.255.255.250 unknown Reserved 8->24 13 chrome.exe 8->13         started        16 AcroCEF.exe 109 11->16         started        process6 dnsIp7 26 139.162.100.28, 49724, 49726, 49727 LINODE-APLinodeLLCUS Netherlands 13->26 28 www.google.com 142.250.184.228, 443, 49731, 49908 GOOGLEUS United States 13->28 18 AcroCEF.exe 4 16->18         started        process8
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2024-11-18 08:01:03 UTC
File Type:
Document
Extracted files:
11
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments