🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5ea77c1d2431eb235ff2d88d412fe737c3fa0c89de871c32b5dc57e1a320caa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pikabot


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: e5ea77c1d2431eb235ff2d88d412fe737c3fa0c89de871c32b5dc57e1a320caa
SHA3-384 hash: 3f74dbc28b3a3a31f1b853b6707377a1579c20c97ef9a7bc27da5a23723a203c17438f0ec826f21d1fda29333ee083e0
SHA1 hash: 636bd7c1d93126e39c4b4ae7316946c0350e65b0
MD5 hash: 1ccb0807ef5add8105cc16de6e1e0934
humanhash: mars-ceiling-vermont-fifteen
File name:SIMILIQUED.pdf
Download: download sample
Signature Pikabot
File size:205'605 bytes
First seen:2023-12-11 22:57:27 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:iaOPnPo8nwr8cLaDCuVDDM/5ZWWCNPtdpFA:iaqPpnNTBVD05sTPpFA
TLSH T15E1412552A1BC417D6DE8F58EE2890EED27E2E1B2448FB28CC278767A31452CDF27474
Reporter proxylife
Tags:pdf Pikabot

Intelligence


File Origin
# of uploads :
1
# of downloads :
564
Origin country :
US US
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
1.6/10
Score Malicious:
17%
Score Benign:
83%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1359177 Sample: SIMILIQUED.pdf Startdate: 12/12/2023 Architecture: WINDOWS Score: 56 21 flowersaffairs.com 2->21 37 Multi AV Scanner detection for domain / URL 2->37 39 Antivirus detection for URL or domain 2->39 8 chrome.exe 1 2->8         started        11 Acrobat.exe 20 74 2->11         started        signatures3 process4 dnsIp5 25 192.168.2.4 unknown unknown 8->25 27 192.168.2.6 unknown unknown 8->27 29 239.255.255.250 unknown Reserved 8->29 13 chrome.exe 8->13         started        16 AcroCEF.exe 73 11->16         started        process6 dnsIp7 31 flowersaffairs.com 64.31.47.66 LIMESTONENETWORKSUS United States 13->31 33 clients.l.google.com 142.250.189.142 GOOGLEUS United States 13->33 35 83 other IPs or domains 13->35 18 AcroCEF.exe 2 16->18         started        process8 dnsIp9 23 23.46.212.24 AKAMAI-ASUS United States 18->23
Threat name:
Document-PDF.Trojan.Pikabot
Status:
Malicious
First seen:
2023-12-11 19:34:51 UTC
File Type:
Document
Extracted files:
1
AV detection:
12 of 37 (32.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments