14986da600df26fdb4e435cf01b6be4e5fffcc001059609070a2de701496bdde
Classification: Malicious
14986da600df26fdb4e435cf01b6be4e5fffcc001059609070a2de701496bdde is a malicious file sample. Linked to Bitter activity. Detected by 25 antivirus engines.
Detection summary
- 25 antivirus detections (52% detection ratio)
- 0 IDS alerts
- 7 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-05-23 06:45:05 |
2023-05-23 07:45:16 |
|
|
| Bitter |
MalwareBazaar Abuse.ch |
2022-05-13 08:17:37 |
2022-05-13 08:17:37 |
malicious-activity
|
G1002 BITTER
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2022-05-13 08:17:37 |
2022-05-13 08:17:37 |
malicious-activity
|
|
Sample information
- Filenames
- 14986da600df26fdb4e435cf01b6be4e5fffcc001059609070a2de701496bdde, file
- File type
- Microsoft Excel 2007+
- Size
- 11486 bytes
- MD5
98ed55d0388130077a6e4f45b2dd6458
- SHA-1
83e87be33f31fa21d21b605765debbe5e30768b2
- SHA-256
14986da600df26fdb4e435cf01b6be4e5fffcc001059609070a2de701496bdde
- First indexed
- 2022-05-13 09:15:03
- Last updated
- 2026-04-05 06:35:46
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.MSOffice.CVE-2018-0802.3!c |
| MicroWorld-eScan | Trojan.GenericKD.60045464 |
| FireEye | Trojan.GenericKD.60045464 |
| McAfee | RDN/exploit-ole2.gen |
| Alibaba | Trojan:Win32/MalDoc.ali1000146 |
| Symantec | Trojan.Gen.NPE |
| ESET-NOD32 | Win32/Exploit.CVE-2018-0798.A |
| Avast | Other:Malware-gen [Trj] |
| ClamAV | Ole2.Exploit.ZxxZDownloader-9944376-0 |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| BitDefender | Trojan.GenericKD.60045464 |
| Ad-Aware | Trojan.GenericKD.60045464 |
| TACHYON | Suspicious/XOX.CVE-2018-0798 |
| DrWeb | Exploit.CVE-2018-0798.4 |
| McAfee-GW-Edition | RDN/exploit-ole2.gen |
| Emsisoft | Trojan.GenericKD.60045464 (B) |
| GData | Generic.Trojan.Agent.E13IFZ |
| Avira | EXP/W97M.CVE-2018-0802.munvt |
| Microsoft | Trojan:Script/Sabsik.FL.B!ml |
| ViRobot | XLS.Z.CVE-2018-0798.11486 |
| ZoneAlarm | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |
| Cynet | Malicious (score: 99) |
| AhnLab-V3 | OLE/Cve-2018-0798.Gen |
| MAX | malware (ai score=87) |
| AVG | Other:Malware-gen [Trj] |
Process list
| Name | Command line |
| EXCEL.EXE | /dde |
| EQNEDT32.EXE | -Embedding |
| WerFault.exe | -u -p 6572 -s 844 |
| WerFault.exe | -u -p 6572 -s 852 |
| EQNEDT32.EXE | -Embedding |
| WerFault.exe | -u -p 4852 -s 796 |
| WerFault.exe | -u -p 4852 -s 804 |