🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b54371228b9a9657abe03b118247942d5b61370b36bbdd6027abc178b8a09e35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: b54371228b9a9657abe03b118247942d5b61370b36bbdd6027abc178b8a09e35
SHA3-384 hash: c571575d75f82e530877e143c0088f0e9ea7edb95d96d522b5d0ca554798aacd7b5184c9d1a709e37bdb90310cb28d08
SHA1 hash: 60ac79d017cc60bf920270e1684ddcc1364a0917
MD5 hash: d6fd3360597cb2429f4b0a3c4231a44e
humanhash: lake-butter-early-massachusetts
File name:NVI_utasitas.pdf
Download: download sample
File size:449'346 bytes
First seen:2026-04-11 21:20:10 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:MmotOpUQ2Rbv7rBPadCJxrR7iuehcJhswhO:MmySUVv7r0CDrR7nehcJhswhO
TLSH T17AA4B32561FB157CE5A762F0663D7310822E34ECDB6D4A2E329A214B06F4F78CAD6317
Magika pdf
Reporter smica83
Tags:HUN pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
360
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
trojan phish sage
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
base64 fingerprint macros
Label:
Benign
Suspicious Score:
9/10
Score Malicious:
9%
Score Benign:
91%
Verdict:
Malicious
File Type:
pdf
First seen:
2026-04-02T03:56:00Z UTC
Last seen:
2026-04-02T07:29:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis
Score:
48 / 100
Signature
AI detected malicious page (phishing or scam)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1896943 Sample: NVI_utasitas.pdf Startdate: 11/04/2026 Architecture: WINDOWS Score: 48 22 stun.services.mozilla.com 2->22 32 AI detected malicious page (phishing or scam) 2->32 8 chrome.exe 2 2->8         started        11 Acrobat.exe 20 59 2->11         started        13 chrome.exe 2->13         started        signatures3 process4 dnsIp5 24 192.168.2.4, 138, 443, 49351 unknown unknown 8->24 15 chrome.exe 8->15         started        18 AcroCEF.exe 104 11->18         started        process6 dnsIp7 26 www.google.com 142.251.155.119, 443, 49744 GOOGLEUS United States 15->26 28 142.251.156.119, 443, 49761 GOOGLEUS United States 15->28 30 2 other IPs or domains 15->30 20 AcroCEF.exe 3 18->20         started        process8
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
PDF /AA PDF /OpenAction PDF Contains AutoAction
Threat name:
Document-PDF.Trojan.Malgent
Status:
Malicious
First seen:
2026-04-02 15:52:29 UTC
File Type:
Document
Extracted files:
16
AV detection:
5 of 23 (21.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments