🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e10d69d66ba22ac3e14100bce8a324db59d15fd1c2a7ce78316d0e3681d3c45c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BumbleBee


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e10d69d66ba22ac3e14100bce8a324db59d15fd1c2a7ce78316d0e3681d3c45c
SHA3-384 hash: b79ba80a5658214b16a8513432eaa3502be411f041a824a8487ae72a4bc382d24b42c50d1f11802e1a03228bff352255
SHA1 hash: 68ba06a44bef88885667dc4cf026b02b61e887ee
MD5 hash: f09c96b3c6bc4745c8fade1a8a47591c
humanhash: kitten-oscar-stream-pennsylvania
File name:nclase_file_04.20.23.pdf
Download: download sample
Signature BumbleBee
File size:197'184 bytes
First seen:2023-04-20 19:18:30 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:1JTW6j/rvbWb3OUJLfOcOcOcD/elhF08qZZS20tOVkNUXp7+eQin3qf:rtj6DO2LfOrd82lg8qZZXEUX95QQaf
TLSH T1EF14ADA6FAF2F1EB71C801B11704F13C62957D1AA7B0DC9C386DE9402B96EF126693D1
Reporter 0xToxin
Tags:BUMBLEBEE mc1904 pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
468
Origin country :
IL IL
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
remote
Label:
Benign
Suspicious Score:
3.1/10
Score Malicious:
31%
Score Benign:
69%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Clickable URLs found in PDF pointing to potentially malicious files
Downloads suspicious files via Chrome
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 851211 Sample: nclase_file_04.20.23.pdf Startdate: 20/04/2023 Architecture: WINDOWS Score: 48 37 Clickable URLs found in PDF pointing to potentially malicious files 2->37 39 Downloads suspicious files via Chrome 2->39 8 chrome.exe 17 8 2->8         started        12 AcroRd32.exe 15 39 2->12         started        process3 dnsIp4 27 239.255.255.250 unknown Reserved 8->27 25 C:\Users\user\...\doc_12QICZ_85.zip (copy), Zip 8->25 dropped 14 chrome.exe 8->14         started        17 unarchiver.exe 4 8->17         started        19 RdrCEF.exe 66 12->19         started        file5 process6 dnsIp7 29 biznessfarm.buzz 95.164.18.186, 443, 49704 NASSIST-ASGI Gibraltar 14->29 31 www.google.com 142.250.180.164, 443, 49707, 49745 GOOGLEUS United States 14->31 35 4 other IPs or domains 14->35 21 7za.exe 2 17->21         started        33 192.168.2.1 unknown unknown 19->33 process8 process9 23 conhost.exe 21->23         started       
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments