🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 faa51a4e93265bad56fa4bcec9bcc968d6d11b0b2b01bc7d82cfee3b324031f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: faa51a4e93265bad56fa4bcec9bcc968d6d11b0b2b01bc7d82cfee3b324031f6
SHA3-384 hash: 38d91a5513d9290acdb6825ca18234b8f59eea1b60d02fe5f172c2fea2f12ccab50b1fe252757154c9bed670e192d7d9
SHA1 hash: b4b25aaaf07f4678688cefc4344a9f078f5e49b8
MD5 hash: f2406ac5774b95505b3d587465b2740d
humanhash: fix-yellow-yankee-crazy
File name:lnvoice_1541436948.pdf
Download: download sample
File size:16'795 bytes
First seen:2023-09-18 12:00:14 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:grfVsuD4nuVC2GGGGzoTLb1zM7cfZsOvcAQd7+DA/:grGKC2GGGGz8b1zEcjvcRFsA/
TLSH T1AB726E2CAF399055F4560F7B021C2747D0AE93D16768657E292F4586BC0BE24EF2C3E6
Reporter JAMESWT_WT
Tags:AgentTesla htlbookingnew pdf TUKHAMTASSER

Intelligence


File Origin
# of uploads :
1
# of downloads :
428
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Malicious
Suspicious Score:
6.4/10
Score Malicious:
64%
Score Benign:
36%
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.expl
Score:
76 / 100
Signature
Connects to many IPs within the same subnet mask (likely port scanning)
Downloads suspicious files via Chrome
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Suspicious execution chain found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1309987 Sample: lnvoice_1541436948.pdf Startdate: 18/09/2023 Architecture: WINDOWS Score: 76 38 www.google.com 2->38 64 Multi AV Scanner detection for domain / URL 2->64 66 Multi AV Scanner detection for submitted file 2->66 68 Connects to many IPs within the same subnet mask (likely port scanning) 2->68 70 2 other signatures 2->70 9 chrome.exe 14 2->9         started        13 AcroRd32.exe 62 2->13         started        signatures3 process4 dnsIp5 50 192.168.2.3 unknown unknown 9->50 34 C:\Users\...\lnvoice__1541436948.js (copy), Unicode 9->34 dropped 36 C:\...\lnvoice__1541436948 (1).js (copy), Unicode 9->36 dropped 15 wscript.exe 1 9->15         started        18 chrome.exe 9->18         started        21 chrome.exe 10 13->21         started        23 chrome.exe 13->23         started        file6 process7 dnsIp8 72 Wscript starts Powershell (via cmd or directly) 15->72 74 Windows Scripting host queries suspicious COM object (likely to drop second stage) 15->74 25 powershell.exe 15 20 15->25         started        40 13.224.214.105 AMAZON-02US United States 18->40 42 13.224.214.11 AMAZON-02US United States 18->42 48 58 other IPs or domains 18->48 44 192.168.2.1 unknown unknown 21->44 46 239.255.255.250 unknown Reserved 21->46 28 chrome.exe 21->28         started        30 chrome.exe 23->30         started        signatures9 process10 dnsIp11 52 dd6qg4wn9ejpd.cloudfront.net 18.238.4.23 AMAZON-02US United States 25->52 54 htlbookingnew.blogspot.com 25->54 56 d9e1c3dd-1fee-48c1-9089-09a70580408e.usrfiles.com 25->56 32 conhost.exe 25->32         started        58 13.224.214.14 AMAZON-02US United States 28->58 60 13.224.214.15 AMAZON-02US United States 28->60 62 29 other IPs or domains 28->62 process12
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2023-09-18 06:05:38 UTC
File Type:
Document
Extracted files:
9
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments