🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f188eec1268fd49bdc7375fc5b77ded657c150875fede1a4d797f818d2514e88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 5


Maldoc score: 15


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f188eec1268fd49bdc7375fc5b77ded657c150875fede1a4d797f818d2514e88
SHA3-384 hash: eb7d6f039d72ba3f2da1431b8acf5ba31e2c223c967d5de27b714c9232541e2e8f5732601a68031f0b570971cd30b1b4
SHA1 hash: f675c0aa46a18a6026f0d541fce6a75688a018aa
MD5 hash: e87b575b2ddfb9d4d692e3b8627e3921
humanhash: pizza-alanine-queen-uncle
File name:f188eec1268fd49bdc7375fc5b77ded657c150875fede1a4d797f818d2514e88.bin
Download: download sample
Signature Lazarus
File size:2'066'432 bytes
First seen:2021-01-22 19:07:50 UTC
Last seen:2022-10-05 10:05:55 UTC
File type:Word file doc
MIME type:application/msword
ssdeep 24576:qXLERj43LTzR9rrS/7dDXMCcZVZD5Akh2ulzm3f0kPvw3o2QgjUNQNNc9y/oRky+:qXLEqC2J3WA753
TLSH 5AA59C969A0C4AEFD94D00B03B2D7F91B3583C41AFDBCA1F6659A9180D2EF58CF0B945
Reporter Arkbird_SOLG
Tags:apt Lazarus maldoc

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 15
Application name is unknown
Office document is in OLE format
Office document contains VBA Macros
OLE dump

MalwareBazaar was able to identify 16 sections in this file using oledump:

Section IDSection sizeSection name
1114 bytesCompObj
2280 bytesDocumentSummaryInformation
3340 bytesSummaryInformation
47030 bytes1Table
5206129 bytesData
6372 bytesMacros/PROJECT
741 bytesMacros/PROJECTwm
81820911 bytesMacros/VBA/ThisDocument
94109 bytesMacros/VBA/_VBA_PROJECT
10514 bytesMacros/VBA/dir
11112 bytesObjectPool/_1649178531/CompObj
1216 bytesObjectPool/_1649178531/OCXNAME
136 bytesObjectPool/_1649178531/ObjInfo
1486 bytesObjectPool/_1649178531/f
150 bytesObjectPool/_1649178531/o
164096 bytesWordDocument
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecFrame1_LayoutRuns when the file is opened and ActiveX objects trigger events
Hex StringR8ItyQ523849747951
Hex StringGjqz476A717A
Hex StringmtSWbE6D7453576245
Hex String1oAm316F416D
Hex StringEROwXn45524F77586E
Hex String9xom39786F6D
Hex StringQiwfn8516977666E38
Hex Stringj1UV6A315556
Hex StringtfcNpv7466634E7076
Hex StringTiA654694136
Hex StringweLjJj77654C6A4A6A
Hex String66jh36366A68
Hex Stringp5lHH670356C484836
Hex StringTGZT54475A54
Hex String7PlVJ637506C564A36
Hex StringzOQ47A4F5134
Hex StringWwxd57777864
Hex Stringg4RT67345254
Hex String66Kjnm36364B6A6E6D
Hex StringEWAV45574156
Hex StringWAVA57415641
Hex String AUAVA204155415641
Hex StringAVAT41564154
Hex String WAVAW205741564157
Hex StringQ510A427D
Hex Stringrla_726C615F
Hex StringO4F0D2E32
Hex StringNfLN4E664C4E
Hex StringmtO6D744F09
Hex String v09760B4B
Hex Stringy779370B25
Hex Stringiivr69697672
Hex String mTCq-206D5443712D
Hex StringAT2C41543243
Hex StringDg44670B30
Hex String.5A2E35410C
Hex StringYR65952360C6561
Hex StringnPPc6E505063
Hex StringLWIi4C574969
Hex StringcgXK6367584B
Hex Stringfz-o667A2D6F
Hex StringhWVS68575653
Hex StringpCtAOh704374414F68
Hex StringieiFrq696569467271
Hex StringyuTY79755459
Hex StringQrb1mP517262316D50
Hex StringLTcu4C546375
Hex StringfrWXkT667257586B54
Hex StringvCIN7643494E
Hex StringjSwLaN6A53774C614E
Hex StringMj3S4D6A3353
Hex StringZ1742p5A3137343270
Hex StringSE2P53453250
Hex String87nJ38376E4A
Hex Stringw981Y7773938315937
Hex StringAPPf41505066
Hex StringfOg3xB664F67337842
Hex String1uA731754137
Hex StringSJiujA534A69756A41
Hex StringYCpE59437045
Hex String7M1u7r374D31753772
Hex String_3AU5F334155
Hex String5rz
Hex Stringtq74710B52
Hex StringeFfS65466653
Hex StringgcL967634C39
Hex Stringm6Jj6D364A6A
Hex Stringg4UX67345558
Hex Stringz31I7A333149
Hex StringHm V486D0956
Hex StringI yQ49097951
Hex StringItj
Hex Stringtltn746C746E
Hex StringqkiN716B694E
Hex Stringu.FI752E4649
Hex String3A2J3341324A
Hex StringMs0F4D733046
Hex String.RY2E525909
Hex StringTwt5477740B
Hex StringRdj.52646A2E
Hex StringEh9L4568394C
Hex StringM4D0A2B0B
Hex StringKV b4B562062
Hex StringmVJD6D564A44
Hex Stringu750A2E7C
Hex StringopW 6i6F7057093669
Hex StringBHgR42486752
Hex Stringg1lm67316C6D
Hex StringwB-j77422D6A
Hex StringnVg0B6E5667
Hex String6360D36786932
Hex StringpY670593620
Hex Stringd064300D3B
Hex String3ww033777730
Hex StringWqKP57714B50
Hex StringShUH53685548
Hex StringTBiX54426958
Hex StringOM6MiE4F4D364D6945
Hex Stringlt6C740D39
Hex StringklV96B6C5639
Hex StringRqC-5271432D
Hex StringG470A2A76
Hex String_pMp5F704D70
Hex StringHuFN4875464E
Hex Stringx780A3A3B722F
Hex StringfwH6677480C
Hex String4p2E34703245
Hex Stringy0D790B61
Hex String-fk82D666B38
Hex Stringt-Tj742D546A
Hex Strings773370A48
Hex StringNEkQ4E456B51
Hex StringD440D096F
Hex StringFYJf46594A66
Hex Stringfunz66756E7A
Hex String5Hsx35487378
Hex StringbbNN62624E4E
Hex Stringl6C0D4839
Hex StringKHu4B487509
Hex String5tjZ35746A5A
Hex StringXW158573109
Hex String7Qdt37516474
Hex StringFlx466C780D
Hex StringSB4-5342342D
Hex Stringe_lg655F6C67
Hex String5CR-3543522D
Hex StringmE7V6D453756
Hex StringXo586F0D4D
Hex StringB2H0C423248
Hex StringVa9Z5661395A
Hex StringWGY857475938
Hex Stringub2r75623272
Hex StringSDm
Hex Stringode0B6F6465
Hex Stringatcu61746375
Hex StringXJrt584A7274
Hex Strings7Ww73375777
Hex StringoP0B6F500B3334
Hex Stringkf6B660A786809
Hex StringwrG7772470D
Hex StringyiSS79695353
Hex StringpY70590C5D
Hex Stringznse7A6E7365
Hex StringgPTJ6750544A
Hex StringcS1n6353316E
Hex String9-1D392D3144
Hex StringDFqL4446714C
Hex Stringz 2L7A20324C
Hex String g_o20675F6F
Hex String4h1
Hex StringPrny50726E79
Hex Stringp7Rn7037526E
Hex StringcPV63505620
Hex StringVCMn56434D6E
Hex Stringiht0B696874
Hex StringPYyv50597976
Hex Stringby3B62793342
Hex StringyYY7959590D
Hex StringwGrg77477267
Hex StringSURK5355524B
Hex StringDAK744414B37
Hex StringxORd784F5264
Hex StringQ-M5512D4D35
Hex String505a35303561
Hex StringcE1.6345312E
Hex String3f3D33663344
Hex StringUROz55524F7A
SuspiciousOpenMay open a file
SuspiciousLibMay run code from a DLL
SuspiciousChrMay attempt to obfuscate specific strings (use option --deobf to deobfuscate)
SuspiciousXorMay attempt to obfuscate specific strings (use option --deobf to deobfuscate)
Suspicious.VariablesMay use Word Document Variables to store and hide data
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
4
# of downloads :
217
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
NG-Opportunity.doc
Verdict:
Malicious activity
Analysis date:
2021-01-21 21:44:11 UTC
Tags:
macros macros-on-open

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with base64 encoded strings
Document exploit detected (creates forbidden files)
Document exploit detected (drops PE files)
Document exploit detected (process start blacklist hit)
Machine Learning detection for sample
Microsoft Office drops suspicious files
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Office process drops PE file
Sigma detected: Microsoft Office Product Spawning Windows Shell
Behaviour
Behavior Graph:
Threat name:
Script-Macro.Trojan.Stratos
Status:
Malicious
First seen:
2021-01-22 03:17:00 UTC
AV detection:
10 of 28 (35.71%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments