28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1

Classification: Malicious

28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1 is a malicious file sample. Linked to Invisimole malware. Detected by 23 antivirus engines.

Detection summary

  • 23 antivirus detections (37% detection ratio)
  • 0 IDS alerts
  • 1 processes observed
  • 1 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Malware families: INVISIMOLE (S0260)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Invisimole Maltiverse 2023-03-31 04:13:54 2023-04-01 00:17:29 malicious-activity S0260 InvisiMole
Ghostwriter Maltiverse 2023-03-31 04:13:55 2023-04-01 00:17:23 malicious-activity
CVE-2017-0199 Hybrid-Analysis 2020-07-29 00:30:15 2020-07-29 00:30:15

Tags

apt

Sample information

Filenames
28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1
File type
Microsoft Word 2007+
Size
595016 bytes
MD5
e7fc03267e47814e23e004e5f3a1205b
SHA-1
e8c4a1a94ee856331d9d571194915bfb48b9231c
SHA-256
28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1
First indexed
2020-07-29 00:30:15
Last updated
2026-04-05 21:30:28

Antivirus detections

EngineDetection
FireEyeTrojan.Groooboor.Gen.19
SymantecTrojan.Mdropper
TrendMicro-HouseCallTROJ_FRS.VSNTGN20
KasperskyHEUR:Trojan-Dropper.MSOffice.SDrop.gen
BitDefenderTrojan.Groooboor.Gen.19
NANO-AntivirusExploit.Xml.CVE-2017-0199.equmby
ViRobotDOC.S.Exploit.595016
EmsisoftTrojan.Groooboor.Gen.19 (B)
TrendMicroTROJ_FRS.VSNTGN20
AviraW97M/Dldr.Agent.pndxf
ArcabitTrojan.Groooboor.Gen.19
AegisLabTrojan.MSWord.Groooboor.4!c
ZoneAlarmHEUR:Trojan-Dropper.MSOffice.SDrop.gen
MicrosoftExploit:O97M/CVE-2017-0199.YF!MTB
AhnLab-V3Dropper/MSOffice.Generic
ALYacExploit.MSOffice.Gen
MAXmalware (ai score=100)
ZonerProbably Heur.W97OleLink
ESET-NOD32DOC/TrojanDownloader.Agent.ARJ
RisingExploit.ExtLink/OFFICE!1.C97A (CLASSIC)
IkarusTrojan.Groooboor
GDataTrojan.Groooboor.Gen.19
Qihoo-360Generic/Trojan.BO.2da

Network contacts

109.120.170.85

DNS requests

docentfx.com

Process list

NameCommand line
WINWORD.EXE/n "C:\28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1.doc"