🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebc7aad321576ec1511158184ea8dbac4e25f91639ef7d44ed7ca3a6a855956a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WSHRAT


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: ebc7aad321576ec1511158184ea8dbac4e25f91639ef7d44ed7ca3a6a855956a
SHA3-384 hash: 12e870dcf6e67566db09d1625ca90f8b6a8ef83c51fec482fc5b4962e930145a20f0dfec1d56fbbdbd8f93ebc61abf8c
SHA1 hash: 093ad90725d2d1560d0a7f327ebacb4dcd20fc3f
MD5 hash: 41e4ae11e3703251a563bee5aad6c0e0
humanhash: mirror-monkey-johnny-music
File name:ORDER-022023.pdf
Download: download sample
Signature WSHRAT
File size:216'990 bytes
First seen:2023-01-02 09:52:01 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:mrRcwHSwA3/3CaovntCc1GZq1VWcXAbTtXSz:0R9hAv3CaoVC1M1VWr6
TLSH T1E4241233590A415ECBDE1A6B71213DC98E5F71327EF5397B09E88A14A5D0F34E86D0AC
Reporter 0xToxin
Tags:pdf PerceptionPoint wshrat


Avatar
0xToxin
download URL:
https://transfer.sh/get/9yiXvu/ORDER-022023.doc.js

Intelligence


File Origin
# of uploads :
1
# of downloads :
424
Origin country :
IL IL
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
2/10
Score Malicious:
2%
Score Benign:
98%
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
20 / 100
Signature
Clickable URLs found in PDF pointing to potentially malicious files
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 776825 Sample: ORDER-022023.pdf Startdate: 02/01/2023 Architecture: WINDOWS Score: 20 18 transfer.sh 2->18 30 Clickable URLs found in PDF pointing to potentially malicious files 2->30 8 AcroRd32.exe 15 45 2->8         started        signatures3 process4 process5 10 chrome.exe 15 13 8->10         started        13 RdrCEF.exe 70 8->13         started        dnsIp6 20 239.255.255.250 unknown Reserved 10->20 15 chrome.exe 10->15         started        22 192.168.2.1 unknown unknown 13->22 process7 dnsIp8 24 transfer.sh 144.76.136.153, 443, 49699 HETZNER-ASDE Germany 15->24 26 www.google.com 142.250.203.100, 443, 49708, 49721 GOOGLEUS United States 15->26 28 4 other IPs or domains 15->28
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2023-01-02 06:48:55 UTC
File Type:
Document
Extracted files:
10
AV detection:
5 of 40 (12.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments