🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6eb8b5986ea95877146adc1c6ed48ca2c304d23bc8a4a904b6e6d22d55bceec3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Fog


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 6eb8b5986ea95877146adc1c6ed48ca2c304d23bc8a4a904b6e6d22d55bceec3
SHA3-384 hash: 22bea2772c3ff4ecb9172c83067bbca4a78833074cf82f4f44292c1f0a0fe95f9c1a2c87c6632e1fb0609abf481ab92a
SHA1 hash: e4721effe1aa5b54fb00f80a6e628a1e3c2d86e3
MD5 hash: f294e7c2f611835afc267b1d46419879
humanhash: beer-colorado-violet-johnny
File name:6eb8b5986ea95877146adc1c6ed48ca2c304d23bc8a4a904b6e6d22d55bceec3.pdf
Download: download sample
Signature Fog
File size:351'978 bytes
First seen:2025-04-04 10:23:55 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:stK5sS3caw12btZxEms/z7/OtEmlNIW2wI:X3vw12btZxEms/v/OtEmEWBI
TLSH T19974A499D5C0ADC0D5160CB7DFA2282DAFB93C5615E68E43B315BAE3CCF2043993E189
Magika pdf
Reporter JAMESWT_WT
Tags:fog hilarious-trifle-d9182e-netlify-app pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
515
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
action cmd evasive exploit form lolbin masquerade phishing
Label:
Benign
Suspicious Score:
3.0/10
Score Malicious:
3%
Score Benign:
7%
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.expl.evad
Score:
100 / 100
Signature
AI detected landing page (webpage, office document or email)
Bypasses PowerShell execution policy
Clickable URLs found in PDF pointing to potentially malicious files
Downloads suspicious files via Chrome
Found suspicious ZIP file
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Performs a network lookup / discovery via ARP
Powershell drops PE file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sigma detected: PowerShell Download and Execution Cradles
Sigma detected: Suspicious Parent Double Extension File Execution
Sigma detected: Suspicious Startup Folder Persistence
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Uses ipconfig to lookup or modify the Windows network settings
Windows shortcut file (LNK) contains suspicious command line arguments
Yara detected Havoc
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1656565 Sample: 2V0pxH0Pam.pdf Startdate: 04/04/2025 Architecture: WINDOWS Score: 100 87 ipinfo.io 2->87 89 hilarious-trifle-d9182e.netlify.app 2->89 91 9 other IPs or domains 2->91 115 Suricata IDS alerts for network traffic 2->115 117 Malicious sample detected (through community Yara rule) 2->117 119 Multi AV Scanner detection for dropped file 2->119 121 12 other signatures 2->121 12 chrome.exe 14 2->12         started        16 Acrobat.exe 20 62 2->16         started        18 chrome.exe 2->18         started        20 2 other processes 2->20 signatures3 process4 dnsIp5 99 192.168.2.5 unknown unknown 12->99 101 192.168.2.4 unknown unknown 12->101 79 C:\Users\user\...\Pay Adjustment.zip (copy), Zip 12->79 dropped 22 unarchiver.exe 4 12->22         started        24 chrome.exe 12->24         started        27 chrome.exe 12->27         started        31 2 other processes 12->31 29 AcroCEF.exe 105 16->29         started        file6 process7 dnsIp8 33 cmd.exe 2 22->33         started        36 7za.exe 2 22->36         started        93 142.250.176.196 GOOGLEUS United States 24->93 95 youtube-ui.l.google.com 142.250.64.78 GOOGLEUS United States 24->95 97 44 other IPs or domains 24->97 39 AcroCEF.exe 2 29->39         started        process9 file10 103 Suspicious powershell command line found 33->103 105 Bypasses PowerShell execution policy 33->105 41 cmd.exe 33->41         started        44 conhost.exe 33->44         started        77 C:\Users\user\...\Pay Adjustment.pdf.lnk, MS 36->77 dropped 46 conhost.exe 36->46         started        signatures11 process12 signatures13 123 Suspicious powershell command line found 41->123 48 powershell.exe 41->48         started        process14 dnsIp15 81 ipinfo.io 34.117.59.81 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 48->81 83 34.234.106.80 AMAZON-AESUS United States 48->83 85 2 other IPs or domains 48->85 73 C:\Users\user\AppData\Local\Temp\ktool.exe, PE32+ 48->73 dropped 75 C:\ProgramData\...\trackerjacker.ps1, ASCII 48->75 dropped 107 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 48->107 109 Suspicious powershell command line found 48->109 111 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 48->111 113 4 other signatures 48->113 53 powershell.exe 48->53         started        55 powershell.exe 48->55         started        57 powershell.exe 48->57         started        59 9 other processes 48->59 file16 signatures17 process18 process19 61 conhost.exe 53->61         started        63 chrome.exe 53->63         started        65 conhost.exe 55->65         started        67 chrome.exe 55->67         started        69 conhost.exe 57->69         started        71 chrome.exe 57->71         started       
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2025-03-25 14:20:51 UTC
File Type:
Document
Extracted files:
5
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments