🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1b6808e43617e6891feb4a2b77e9ad32f9673762829f68e7a1975d48ff8f7c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d1b6808e43617e6891feb4a2b77e9ad32f9673762829f68e7a1975d48ff8f7c4
SHA3-384 hash: eb66c51acb95d0ed80cb02bf3901a0d1a36a19ae56272171b05e1e082b94100a3ad7ed4b07c13ecbc2a9a7bdde7a5846
SHA1 hash: 2fde8bc6dd8e5c5a0a1b84050ef5df57faa34504
MD5 hash: b0c3ebc717d0adb164ecff17218d5573
humanhash: high-wolfram-sierra-massachusetts
File name:FedEx Shipment Arrival Notification AWB# 00117980920.pdf
Download: download sample
File size:51'946 bytes
First seen:2024-01-17 16:56:28 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 192:TOapHXfyVWVZ5GWa2pxTZmE3tu8cSYZEunf:KAsWNGWJpxPu8cB9nf
TLSH T1A5339434FBDBD3958B47995C913E3E736B9191C410D0A6A30D2F4C1BA488F768A43ABC
Reporter e24111111111111
Tags:Andromeda pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
532
Origin country :
GR GR
Vendor Threat Intelligence
Verdict:
Malicious
Labled as:
PowerShell/TrojanDownloader.Agent
Label:
Malicious
Suspicious Score:
5.5/10
Score Malicious:
55%
Score Benign:
45%
Result
Threat name:
n/a
Detection:
suspicious
Classification:
phis
Score:
23 / 100
Signature
Phishing site detected (based on OCR NLP Model)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1376233 Sample: FedEx_Shipment_Arrival_Noti... Startdate: 17/01/2024 Architecture: WINDOWS Score: 23 20 netforum.avectra.com 2->20 34 Phishing site detected (based on OCR NLP Model) 2->34 8 chrome.exe 18 2->8         started        11 Acrobat.exe 55 2->11         started        signatures3 process4 dnsIp5 22 192.168.2.5, 138, 443, 49224 unknown unknown 8->22 24 192.168.2.6 unknown unknown 8->24 26 2 other IPs or domains 8->26 13 chrome.exe 8->13         started        16 AcroCEF.exe 69 11->16         started        process6 dnsIp7 28 www.google.com 142.250.176.196, 443, 49733, 49758 GOOGLEUS United States 13->28 30 142.250.65.161, 443, 49731 GOOGLEUS United States 13->30 32 14 other IPs or domains 13->32 18 AcroCEF.exe 2 16->18         started        process8
Threat name:
Document-PDF.Trojan.Pidief
Status:
Malicious
First seen:
2024-01-17 15:46:56 UTC
File Type:
Document
Extracted files:
7
AV detection:
12 of 23 (52.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

pdf d1b6808e43617e6891feb4a2b77e9ad32f9673762829f68e7a1975d48ff8f7c4

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments