🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d904ea46d611628b5dd8e32c068dd1af2c87b25d47588fb7004d07a7b7d48b00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d904ea46d611628b5dd8e32c068dd1af2c87b25d47588fb7004d07a7b7d48b00
SHA3-384 hash: 889c31fbf4b3c4b420788735cb53a2b03e9c282a297ba690087155b8878566075e9b6fc9d4e6e259d310f59e9b5a6ade
SHA1 hash: a798e72fd3a9960df9644240fe067f2f086899ad
MD5 hash: 30325c9551f3acd9d6ad02e6f01a6d7d
humanhash: hotel-salami-india-angel
File name:Stanley Tools - ScrewFix Exclusive Rewards.pdf
Download: download sample
File size:12'421 bytes
First seen:2024-07-21 13:45:35 UTC
Last seen:2024-07-21 13:46:37 UTC
File type:Word file doc
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 192:CtwxBAOFHoxCCNxtpgoZ22NNBJdfgaDOAk9HWU1jPBEaoI5++v+:aw8ORoxdNxt/ZtNNBQ8khlf4+v+
TLSH T1D542AF3DED9A5461C9938A7DB05E11F5F22C8186A702D40E20D2778ED360F972B2EA8D
TrID 52.2% (.DOCX) Word Microsoft Office Open XML Format document (23500/1/4)
38.8% (.ZIP) Open Packaging Conventions container (17500/1/4)
8.8% (.ZIP) ZIP compressed archive (4000/1)
Reporter cocaman
Tags:doc pdf


Avatar
cocaman
Malicious email (T1566.001)
From: ""8600211007:ID" <jolomivk4iu@htuegwcwl.frsnhuafq.maxiptv.info>" (likely spoofed)
Received: "from DUZPR83CU001.outbound.protection.outlook.com (mail-northeuropeazon11023116.outbound.protection.outlook.com [52.101.67.116]) "
Date: "Sat, 20 Jul 2024 13:54:04 +0000"
Subject: "Re: 17588:ID Surprise! Get a Stanley Tool on Us! ID:ahukt"
Attachment: "Stanley Tools - ScrewFix Exclusive Rewards.pdf"

Intelligence


File Origin
# of uploads :
2
# of downloads :
2'503
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Re_ 80306_ID Your Free Stanley Tool Awaits ___ Just for Being Awesome! ID_dq4a6.msg
Verdict:
No threats detected
Analysis date:
2024-07-21 10:45:58 UTC
Tags:
spam

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/msword
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Gathering data
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2024-07-20 17:10:22 UTC
File Type:
Document
Extracted files:
11
AV detection:
4 of 24 (16.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Word file doc d904ea46d611628b5dd8e32c068dd1af2c87b25d47588fb7004d07a7b7d48b00

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SHA256 8bda3f28d234ce58b9bbd2d3477dbdeb5cc8548a095a579e0aa8b49315702138
  
Dropping
SHA256 70a70d84494772c1855ec6c2f9a16e0fc6cc41bdb0ce3743563ed943b63e07b8
  
Dropping
SHA256 31ea4a6d7d9d66295e740b7d918f5df36300154ea3a39121e81df6cdc48638f8
  
Dropping
SHA256 3f2b6f1111c12a66c3fbb7605d029040763e7f62444d677063af81d7e938a02d
  
Dropping
SHA256 5e0de111fbc9f99dab9067eb9cd883fa916aaf1958d43d4ef07cfd05a2329a54
  
Dropping
SHA256 f3217362f467598e534e935a3f963ce3e4aa50b1cf1e51765ff0f7da644f49f0
  
Dropping
SHA256 8e0034a3e51bbe3c19dbfe8e32caac915744f2c590ee13a86c44f88538344d30
  
Dropping
SHA256 4208f735318492e3173126da434eceff4401e31b9faa06b787f2672fc0ce97bf

Comments