MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d49c2e47c8e14cc01f0a362293c613ea9604e532ff77b879d69895473dfbeb03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
WikiLoader
Vendor detections: 8
| SHA256 hash: | d49c2e47c8e14cc01f0a362293c613ea9604e532ff77b879d69895473dfbeb03 |
|---|---|
| SHA3-384 hash: | 19bf74a7a1c1ee1eede26b728bc5d44ac6b3a61ed977931f88eabd6e2e86f157acbe7992d1b97014bd7cc63d5e831c2c |
| SHA1 hash: | 107f23a22c983e5871c4f5a52fb95b3b75b367da |
| MD5 hash: | 1331131d07f9172ba06bc507cf18bbf0 |
| humanhash: | mars-pasta-aspen-potato |
| File name: | invoice_from_inc_248180.pdf |
| Download: | download sample |
| Signature | WikiLoader |
| File size: | 87'170 bytes |
| First seen: | 2023-07-14 16:25:04 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/pdf |
| ssdeep | 1536:PV9lTZJ2JIbfD224gVprvCJNiN/s9y53p+jZAy91TYTVv4:99RZJXfKwQNiNhmq81YC |
| TLSH | T16583F13ADDC9898CC0C202F665AE3F62025873C34CE48EDD367D80DD5F929ED69752A2 |
| Reporter | |
| Tags: | Gozi pdf Ursnif WikiLoader |
Intelligence
File Origin
# of uploads :
1
# of downloads :
466
Origin country :
USVendor Threat Intelligence
Result
Verdict:
Suspicious
File Type:
PDF File
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Phishing/PDF.MalUrl
Label:
Benign
Suspicious Score:
6/10
Score Malicious:
7%
Score Benign:
93%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Phishing.Generic
Status:
Malicious
First seen:
2023-07-11 15:53:14 UTC
File Type:
Document
Extracted files:
8
AV detection:
10 of 38 (26.32%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.