🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b87cf8c2619dc99fbaa712f3f120fd7b27c93268bcc39c30dd459dfb68ef7231. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: b87cf8c2619dc99fbaa712f3f120fd7b27c93268bcc39c30dd459dfb68ef7231
SHA3-384 hash: ecb27295906032e9ac909ed7b2d0f84de172fde237c312ccc24be148a221606b40350eab8e4df317dac96a62c9afc66a
SHA1 hash: 85b01fafc385df83e39beef92388c00cadc630ef
MD5 hash: 1e6a8dcb5d913cfb17f29fc216aea61f
humanhash: glucose-papa-island-edward
File name:1e6a8dcb5d913cfb17f29fc216aea61f_a_Invoice_8392_from_Spartan Energy Corp..pdf
Download: download sample
File size:10'835 bytes
First seen:2024-03-21 12:08:51 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 192:NdV79LWPmWaqPHkKp20LAjc3gboBZBm0FyKvKqVxutOa1Sf:rVhLJWaqPH+01fZBm0FyWut5K
TLSH T1DB229EE26C3B1C1D93410EA1A98B0B8A1088A4970E5AD673DCC65767389D9E5FC2D2F1
Reporter adrian__luca
Tags:pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
438
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade scam
Label:
Benign
Suspicious Score:
4.8/10
Score Malicious:
48%
Score Benign:
52%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1413190 Sample: 5XRMvnPXYt.pdf Startdate: 21/03/2024 Architecture: WINDOWS Score: 56 21 flagmatilo.com 2->21 37 Multi AV Scanner detection for domain / URL 2->37 39 Multi AV Scanner detection for submitted file 2->39 8 chrome.exe 9 2->8         started        11 Acrobat.exe 20 67 2->11         started        signatures3 process4 dnsIp5 25 192.168.2.5, 443, 49374, 49703 unknown unknown 8->25 27 192.168.2.8 unknown unknown 8->27 29 239.255.255.250 unknown Reserved 8->29 13 chrome.exe 8->13         started        16 AcroCEF.exe 104 11->16         started        process6 dnsIp7 31 www.google.com 142.250.65.228, 443, 49728, 49739 GOOGLEUS United States 13->31 33 google.com 13->33 35 flagmatilo.com 13->35 18 AcroCEF.exe 2 16->18         started        process8 dnsIp9 23 23.47.168.24, 443, 49715 AKAMAI-ASUS United States 18->23
Threat name:
Document-PDF.Trojan.Scam
Status:
Malicious
First seen:
2024-03-20 15:03:01 UTC
File Type:
Document
Extracted files:
7
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

pdf b87cf8c2619dc99fbaa712f3f120fd7b27c93268bcc39c30dd459dfb68ef7231

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments