🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb28f3b06eb6fa39fe8d0fb26c8dfa56223bc9a903318e940d8db8206d7ffdb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: eb28f3b06eb6fa39fe8d0fb26c8dfa56223bc9a903318e940d8db8206d7ffdb3
SHA3-384 hash: 6b1f2f4816bfef5b1ceb43256c5e909c7bad9f7645bd293302ef17072852c98a04fb8b621d0b38cd54abd42e943f3bb8
SHA1 hash: 3b294a4560fdad334379b270089d5d3bbd28a96f
MD5 hash: 551c406e51047d4a67e0e164eb64c150
humanhash: nine-march-fruit-fillet
File name:FACT20039409002.pdf
Download: download sample
File size:26'455 bytes
First seen:2024-07-01 20:36:45 UTC
Last seen:Never
File type: pdf
MIME type:application/octet-stream
ssdeep 768:ZssccKIEsROehZechPcgqwBoaOGQv036WZ333f:ukd/hZHhPcPgN6g3/
TLSH T158C2F15C652E260C868AA3B1D84920CD16D743405BF778B23FD5C3EE0FA893DB4B9C99
Reporter marcvspt
Tags:malware pdf vbs windows


Avatar
marcvspt
Drop a zip downloaded in https://bit.ly/45UYm9t

Intelligence


File Origin
# of uploads :
1
# of downloads :
559
Origin country :
MX MX
Vendor Threat Intelligence
Verdict:
Suspicious
Score:
50%
Tags:
Execution Infostealer Network Ransomware
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
AI detected suspicious PDF
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1465852 Sample: FACT20039409002.pdf Startdate: 02/07/2024 Architecture: WINDOWS Score: 22 16 AI detected suspicious PDF 2->16 7 Acrobat.exe 74 2->7         started        process3 process4 9 AcroCEF.exe 106 7->9         started        process5 11 AcroCEF.exe 2 9->11         started        dnsIp6 14 23.47.168.24, 443, 49721 AKAMAI-ASUS United States 11->14
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

pdf eb28f3b06eb6fa39fe8d0fb26c8dfa56223bc9a903318e940d8db8206d7ffdb3

(this sample)

Comments