🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c906ab1c58ac70fece30126edbb043f2ff8ca7da614f2e2a0f3c98a42c8a2431. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c906ab1c58ac70fece30126edbb043f2ff8ca7da614f2e2a0f3c98a42c8a2431
SHA3-384 hash: 85bacecbc075ce625ca30c1ffd735124fbec14b97ef778017ce80e7de324ed30012994824c494a8b26ad14002cd16fce
SHA1 hash: 40771228c498f7c115a3db6e451b4b12ac4bdef4
MD5 hash: 55abe9221df1a35a543673a4beae9b2e
humanhash: alanine-hamper-ceiling-romeo
File name:FACTURA 1_ QUINCENA JULIO.pdf
Download: download sample
File size:240'687 bytes
First seen:2023-07-31 06:52:00 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:F03ahoiZy+vUsHvfenYBJq+xTmRclWlV3MOuEz7wm:a3ahoeZHOYCaK/VcC7wm
TLSH T1CC3412E111F5C7118A5950B39076EFF8D1D3B4E6CAF0978A59832B2D1A69E340B7AE0C
Reporter JAMESWT_WT
Tags:pdf pw-1786

Intelligence


File Origin
# of uploads :
1
# of downloads :
414
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
phishing phishing
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
1%
Score Benign:
99%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Clickable URLs found in PDF pointing to potentially malicious files
Downloads suspicious files via Chrome
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1282936 Sample: FACTURA_1__QUINCENA_JULIO.pdf Startdate: 31/07/2023 Architecture: WINDOWS Score: 56 39 Multi AV Scanner detection for submitted file 2->39 41 Clickable URLs found in PDF pointing to potentially malicious files 2->41 43 Downloads suspicious files via Chrome 2->43 8 chrome.exe 8 2->8         started        12 AcroRd32.exe 15 39 2->12         started        process3 dnsIp4 35 192.168.2.5 unknown unknown 8->35 37 239.255.255.250 unknown Reserved 8->37 25 C:\Users\user\Downloads\6d9cob.zip (copy), Zip 8->25 dropped 14 unarchiver.exe 4 8->14         started        16 chrome.exe 8->16         started        19 RdrCEF.exe 65 12->19         started        file5 process6 dnsIp7 21 7za.exe 2 14->21         started        27 clients.l.google.com 142.250.203.110, 443, 49709 GOOGLEUS United States 16->27 29 www.google.com 172.217.168.68, 443, 49712, 49720 GOOGLEUS United States 16->29 33 3 other IPs or domains 16->33 31 192.168.2.1 unknown unknown 19->31 process8 process9 23 conhost.exe 21->23         started       
Threat name:
Document-PDF.Phishing.Generic
Status:
Malicious
First seen:
2023-07-29 08:44:00 UTC
File Type:
Document
Extracted files:
5
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments