MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bdf9fffe1c9ffbeec307c536a2369eefb2a2c5d70f33a1646a15d6d152c2a6fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bdf9fffe1c9ffbeec307c536a2369eefb2a2c5d70f33a1646a15d6d152c2a6fa
SHA3-384 hash: 457c82029caa202f34a4dfd826c9ca6ac36cb9b03016d808249ab9733353911d39c08be61f4a010c4e7760be49456797
SHA1 hash: 2fb28fe0ed05be9da96648e7e44da8b50dc26159
MD5 hash: d58d2127453e056544d8b6413e7836ac
humanhash: stairway-spring-xray-purple
File name:2FB28FE0ED05BE9DA96648E7E44DA8B50DC26159
Download: download sample
Signature Lazarus
File size:1'697'280 bytes
First seen:2021-01-25 21:41:55 UTC
Last seen:2021-01-25 23:51:50 UTC
File type:unknown
MIME type:application/msword
ssdeep 24576:9FZZXCOsUmI+pduys3MAgfr7GDfnp/BXDQQJoJyoTcTjUDMnfq:9ZX0UyAQBOU
TLSH FA75D1DFDA1C468FE9CD007A4B2E6F95FBA50C01AFDB4B07421266141DE9B28FB4B950
Reporter c3rb3ru5d3d53c2
Tags:Lazarus

Intelligence


File Origin
# of uploads :
2
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-Macro.Trojan.Ymacco
Status:
Malicious
First seen:
2020-06-16 02:59:14 UTC
File Type:
Document
Extracted files:
22
AV detection:
10 of 31 (32.26%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments