MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be17fdbe8d7e674ec397cd457dda1b78824ed6597cdef665d1adbf31eaf58d66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: be17fdbe8d7e674ec397cd457dda1b78824ed6597cdef665d1adbf31eaf58d66
SHA3-384 hash: 394724a4b434778df027b52cdac939c9d5805bfdabee5d3ed4ecf5ecc0b9f870c6aca9673f81e26de2667eb882582983
SHA1 hash: e2d97f09d437ed8e9f353e7e4e1aba0dd486ba7b
MD5 hash: 389172d2794d789727b9f7d01ec27f75
humanhash: december-blue-king-apart
File name:be17fdbe8d7e674ec397cd457dda1b78824ed6597cdef665d1adbf31eaf58d66
Download: download sample
Signature Lazarus
File size:1'336'925 bytes
First seen:2021-03-22 13:55:13 UTC
Last seen:2021-05-06 13:12:47 UTC
File type:unknown
MIME type:application/octet-stream
ssdeep 24576:E8y4CJUMXZ5y/SAU0jIYLQKfV0BqOwxrtX0aIVBEONwz40kE7ooys:6pVXZEZU0jDLtxrtIDEOeJooys
TLSH 5E5533F8415065A3C8B77DFBDB55E342F4132A8BE8FD609A1EF16580DA989208FB3417
Reporter Arkbird_SOLG
Tags:apt cve-2017-0199 Lazarus maldoc


Avatar
ArkbirdDevil
Thanks to @c3rb3ru5d3d53c for the sample

Intelligence


File Origin
# of uploads :
2
# of downloads :
190
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Document-Office.Exploit.CVE-2017-0199
Status:
Malicious
First seen:
2020-08-10 23:39:53 UTC
AV detection:
11 of 47 (23.40%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments