MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e74eaf39558da4a4c5191eec8859fea267da4ad94a1f908bcc29c48543f8b90c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: e74eaf39558da4a4c5191eec8859fea267da4ad94a1f908bcc29c48543f8b90c
SHA3-384 hash: 893a48c00b634f2de84f68e39059573d160a6052b7348abc4fc6e1ca1be449e7a10315e7364de27e305682e2c9a0b57d
SHA1 hash: 37836be98352903efa41c16a5d7de730d1b9d992
MD5 hash: ab4b2b9cbe419b5d0dfbfd546094429f
humanhash: uniform-oklahoma-hydrogen-oxygen
File name:copyTT.ppam
Download: download sample
File size:114'564 bytes
First seen:2022-02-03 14:29:18 UTC
Last seen:Never
File type:PowerPoint file ppam
MIME type:application/vnd.openxmlformats-officedocument.presentationml.presentation
ssdeep 3072:vrGMm7A60F+gusBxXspFM6CHvTnD4brjUN/:vzXxusBcy6CHvTUk
TLSH T142B3012894A14663C6234435DC7CC8E2544B0D47A924BE0FB8E1B9879B7DBE9375E3CC
Reporter abuse_ch
Tags:ppam

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
Legacy PowerPoint File with Macro
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm evasive macros macros-on-open mshta
Label:
Malicious
Suspicious Score:
9.9/10
Score Malicious:
1%
Score Benign:
0%
Result
Verdict:
UNKNOWN
Details
Macro with Startup Hook
Detected macro logic that will automatically execute on document open. Most malware contains some execution hook.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2022-02-03 07:58:27 UTC
File Type:
Document
Extracted files:
48
AV detection:
11 of 43 (25.58%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence
Behaviour
Checks processor information in registry
Creates scheduled task(s)
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Modifies system certificate store
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Drops file in System32 directory
Checks computer location settings
Executes dropped EXE
Sets service image path in registry
Suspicious use of NtCreateProcessExOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

PowerPoint file ppam e74eaf39558da4a4c5191eec8859fea267da4ad94a1f908bcc29c48543f8b90c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments