MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d3c39976ec6f4bf43f4cce7cbe52a5f83b1732fb97a9a521db9c57db2ba3bd5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6d3c39976ec6f4bf43f4cce7cbe52a5f83b1732fb97a9a521db9c57db2ba3bd5
SHA3-384 hash: 2dd470c4390bc5f74a9c8da01b6650f46f28f8c48a08798c7a9a1b832454cfa532f393ab792e96d6f38ce0df39edbc06
SHA1 hash: 7f496b7947ae4f78e67a68a1bdd24e6308d9f055
MD5 hash: 5040ef90824371a0bd0acaa36263553b
humanhash: burger-sink-ink-wyoming
File name:image_vba.fpx
Download: download sample
File size:45'568 bytes
First seen:2020-03-31 18:06:07 UTC
Last seen:Never
File type:unknown
MIME type:application/vnd.ms-office
ssdeep 192:AZEtie5nFKU8wqrSz2p+pyqdEG2KJ2Se5nCjDfbWUz5QQ/aJP3Em13BE:ACie90R+pBwKHekjjqUzDO3Emx2
TLSH 87233B047753E096C5A19635CDFAF6FE36657C00EE2E932730E93F2F38B9580991A218
Reporter BazaarDidier
Tags:didierstevens


Avatar
BazaarDidier
This is a PoC: a FlashPix image with VBA code.
To be clear: FlashPix format does not support VBA, the code that I embedded can not execute when viewing the picture.

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Document-Word.Trojan.Kryptik
Status:
Malicious
First seen:
2020-01-16 07:34:54 UTC
File Type:
Binary (Archive)
Extracted files:
19
AV detection:
13 of 30 (43.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments