28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1
Classification: Malicious
28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1 is a malicious file sample. Linked to Invisimole malware. Detected by 23 antivirus engines.
Detection summary
- 23 antivirus detections (37% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Invisimole |
Maltiverse |
2023-03-31 04:13:54 |
2023-04-01 00:17:29 |
malicious-activity
|
S0260 InvisiMole
|
| Ghostwriter |
Maltiverse |
2023-03-31 04:13:55 |
2023-04-01 00:17:23 |
malicious-activity
|
|
| CVE-2017-0199 |
Hybrid-Analysis |
2020-07-29 00:30:15 |
2020-07-29 00:30:15 |
|
|
Sample information
- Filenames
- 28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1
- File type
- Microsoft Word 2007+
- Size
- 595016 bytes
- MD5
e7fc03267e47814e23e004e5f3a1205b
- SHA-1
e8c4a1a94ee856331d9d571194915bfb48b9231c
- SHA-256
28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1
- First indexed
- 2020-07-29 00:30:15
- Last updated
- 2026-04-05 21:30:28
Antivirus detections
| Engine | Detection |
| FireEye | Trojan.Groooboor.Gen.19 |
| Symantec | Trojan.Mdropper |
| TrendMicro-HouseCall | TROJ_FRS.VSNTGN20 |
| Kaspersky | HEUR:Trojan-Dropper.MSOffice.SDrop.gen |
| BitDefender | Trojan.Groooboor.Gen.19 |
| NANO-Antivirus | Exploit.Xml.CVE-2017-0199.equmby |
| ViRobot | DOC.S.Exploit.595016 |
| Emsisoft | Trojan.Groooboor.Gen.19 (B) |
| TrendMicro | TROJ_FRS.VSNTGN20 |
| Avira | W97M/Dldr.Agent.pndxf |
| Arcabit | Trojan.Groooboor.Gen.19 |
| AegisLab | Trojan.MSWord.Groooboor.4!c |
| ZoneAlarm | HEUR:Trojan-Dropper.MSOffice.SDrop.gen |
| Microsoft | Exploit:O97M/CVE-2017-0199.YF!MTB |
| AhnLab-V3 | Dropper/MSOffice.Generic |
| ALYac | Exploit.MSOffice.Gen |
| MAX | malware (ai score=100) |
| Zoner | Probably Heur.W97OleLink |
| ESET-NOD32 | DOC/TrojanDownloader.Agent.ARJ |
| Rising | Exploit.ExtLink/OFFICE!1.C97A (CLASSIC) |
| Ikarus | Trojan.Groooboor |
| GData | Trojan.Groooboor.Gen.19 |
| Qihoo-360 | Generic/Trojan.BO.2da |
Process list
| Name | Command line |
| WINWORD.EXE | /n "C:\28cd09ecad4149eec8665edf79c1c2036df67375f964e7e18a101ca88fe5f8e1.doc" |