🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d49c2e47c8e14cc01f0a362293c613ea9604e532ff77b879d69895473dfbeb03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WikiLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d49c2e47c8e14cc01f0a362293c613ea9604e532ff77b879d69895473dfbeb03
SHA3-384 hash: 19bf74a7a1c1ee1eede26b728bc5d44ac6b3a61ed977931f88eabd6e2e86f157acbe7992d1b97014bd7cc63d5e831c2c
SHA1 hash: 107f23a22c983e5871c4f5a52fb95b3b75b367da
MD5 hash: 1331131d07f9172ba06bc507cf18bbf0
humanhash: mars-pasta-aspen-potato
File name:invoice_from_inc_248180.pdf
Download: download sample
Signature WikiLoader
File size:87'170 bytes
First seen:2023-07-14 16:25:04 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:PV9lTZJ2JIbfD224gVprvCJNiN/s9y53p+jZAy91TYTVv4:99RZJXfKwQNiNhmq81YC
TLSH T16583F13ADDC9898CC0C202F665AE3F62025873C34CE48EDD367D80DD5F929ED69752A2
Reporter k3dg3___
Tags:Gozi pdf Ursnif WikiLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
466
Origin country :
US US
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
6/10
Score Malicious:
7%
Score Benign:
93%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Phishing.Generic
Status:
Malicious
First seen:
2023-07-11 15:53:14 UTC
File Type:
Document
Extracted files:
8
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

WikiLoader

pdf d49c2e47c8e14cc01f0a362293c613ea9604e532ff77b879d69895473dfbeb03

(this sample)

  
Dropping
912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35
  
Delivery method
Distributed via e-mail attachment

Comments