MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff995449039b12666054de503dc9fe5802b4a6e688277eeb06e8d36624dfd7a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 8 File information Comments

SHA256 hash: ff995449039b12666054de503dc9fe5802b4a6e688277eeb06e8d36624dfd7a2
SHA3-384 hash: d13d380c48f76667865d00a97aaddc89439f5625efe33b10436f467d22d0b1aa77ae0e1791c0d02764a27910b4b5f28a
SHA1 hash: a1d12806f0a171db9cd3fd552a491ebde6d8ae38
MD5 hash: c8e8fff04c449d420104c91a801eedd2
humanhash: nebraska-uranus-social-stream
File name:ntp.zip
Download: download sample
File size:734'935 bytes
First seen:2023-09-26 12:31:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:CzC9GWG/4wPJ9H/mxZHxLoNS42LaN5JNoIdvnQ9qngBO6dw0Jhx8dc1L:HTbwB9H/QXoS42LaN+IdqoqOowYh6dML
TLSH T157F4330FC8D7E1D2A34EBA61136B255D1FC0EF21716D6327E12F1B69ACCE6D32209166
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:103-38-236-46 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
IT IT
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:ntp.doc.lnk
File size:2'133 bytes
SHA256 hash: 93ef3ba4b4896b56850ef0a5f894155c163fe6d86fd5a70134b38ee1a7e2447a
MD5 hash: 10a485b8c65306f6e992e68ab96bd6b6
MIME type:application/octet-stream
File name:ntp.txt
File size:5 bytes
SHA256 hash: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
MD5 hash: 5d41402abc4b2a76b9719d911017c592
MIME type:text/plain
File name:ntp.doc
File size:737'103 bytes
SHA256 hash: 639b49204f54f5038e12b053aba3cfc32111df6c8df97d220164db92c96114ed
MD5 hash: db5491b172b6d1192d7bf6b569c44c9d
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive macros-on-open vbastomped
Result
Verdict:
MALICIOUS
Details
Macro with Startup Hook
Detected macro logic that will automatically execute on document open. Most malware contains some execution hook.
Macro with File System Write
Detected macro logic that can write data to the file system.
Threat name:
Win32.Trojan.AggBITSAbuse
Status:
Malicious
First seen:
2023-09-26 12:30:30 UTC
File Type:
Binary (Archive)
Extracted files:
23
AV detection:
13 of 23 (56.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:office_document_vba
Author:Jean-Philippe Teissier / @Jipe_
Description:Office document with embedded VBA
Reference:https://github.com/jipegit/
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip ff995449039b12666054de503dc9fe5802b4a6e688277eeb06e8d36624dfd7a2

(this sample)

  
Delivery method
Distributed via web download

Comments