🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da9c3deb08bfc6a2e7930a4c8f1bd81b5ebffbb09b44027c74ea41ebf7149f8b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: da9c3deb08bfc6a2e7930a4c8f1bd81b5ebffbb09b44027c74ea41ebf7149f8b
SHA3-384 hash: 0a57c735769a1ee9de1c28e44ebda6c425c87bdc23e9dc1c6e16d3c05753348c1a3987b727d0e4fe793e804794906e97
SHA1 hash: 294d792e066dbda1d0b45005a2aaa117f56442a7
MD5 hash: 309e9ca72fafe0247cc84fbebf448bbc
humanhash: fifteen-ink-asparagus-seventeen
File name:CSGMEUSDRAI-22-S-00034-1.pdf
Download: download sample
File size:233'615 bytes
First seen:2022-03-08 12:26:56 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:2TRdtSvtQzbFs2pbf82T+1fA9VqRrhqKDt/4m:2TLAvWb+2pzRT+1f2WhqKpgm
TLSH T1A43422EF034EAC7AC05016064D4BCDE3911E40556EA0B5BBAF423BDAA78FE75CA4417D
Reporter proxylife
Tags:Lokibot pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
749
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
control.exe embedequation exploit shell32.dll shellcode VelvetSweatshop
Label:
Malicious
Suspicious Score:
5.2/10
Score Malicious:
53%
Score Benign:
47%
Threat name:
Document-PDF.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2022-03-08 02:40:19 UTC
File Type:
Document
Extracted files:
56
AV detection:
17 of 42 (40.48%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments