🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 887fda691d4659af5ad5b1f5a51fc04335fdb55e53a7930be438e56f1e394edd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 887fda691d4659af5ad5b1f5a51fc04335fdb55e53a7930be438e56f1e394edd
SHA3-384 hash: 709ad4542fd1205e2ecc3471b27ea7ec521ce1227d0678ba5c21e58692d8321006f63a0b9d35d85a503a2e65447782cd
SHA1 hash: 41af055a0c83b965f3ae872ebeaf5025856f888e
MD5 hash: 13ff15ac54a297796e558bb96feaacfd
humanhash: utah-west-freddie-twelve
File name:887fda691d4659af5ad5b1f5a51fc04335fdb55e53a7930be438e56f1e394edd
Download: download sample
Signature Lazarus
File size:2'559'497 bytes
First seen:2021-03-22 13:54:36 UTC
Last seen:Never
File type:unknown
MIME type:application/octet-stream
ssdeep 49152:uA3UCoJQwlLIM7pohAl3Q5mCtd/IlB34KmodGAX4zHamEUmVGVPzdt0yUq:uAuJQnEoKl3OnID3TNOzHamEUmV2PgE
TLSH C8C533F4628B9585CF2D3932C58CC5E9AC8B8FB7C3B72498767869B5E4D2D11CF21214
Reporter Arkbird_SOLG
Tags:apt Lazarus maldoc


Avatar
ArkbirdDevil
Thanks to @c3rb3ru5d3d53c for the sample

Intelligence


File Origin
# of uploads :
1
# of downloads :
197
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Document-Office.Trojan.Heuristic
Status:
Malicious
First seen:
2020-10-13 14:42:52 UTC
AV detection:
5 of 47 (10.64%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments