471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8
Classification: Malicious
471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8 is a malicious file sample. Linked to Bitter activity. Detected by 54 antivirus engines.
Detection summary
- 54 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BITTER (G1002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitter | MalwareBazaar Abuse.ch | 2022-05-13 08:17:44 | 2022-05-13 08:17:44 | malicious-activity | G1002 BITTER |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-05-13 08:17:44 | 2022-05-13 08:17:44 | malicious-activity |
Sample information
- Filenames
- 471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8
- File type
- application/octet-stream
- MD5
b90f8e14181f04d2b95575a4ad8fa0b7- SHA-1
dbfc24ba97158d97082be5180bbf20bbbb3d0761- SHA-256
471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8- First indexed
- 2022-05-13 09:15:03
- Last updated
- 2026-07-10 00:42:07
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Multi.Generic.4!c |
| ClamAV | Ole2.Exploit.ZxxZDownloader-9944376-0 |
| McAfee | RDN/exploit-ole2.gen |
| Alibaba | Trojan:Win32/MalDoc.ali1000146 |
| Symantec | Trojan.Gen.NPE |
| ESET-NOD32 | Win32/Exploit.CVE-2018-0798.A |
| Avast | Other:Malware-gen [Trj] |
| Cynet | Malicious (score: 99) |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| BitDefender | Trojan.GenericKD.39628153 |
| MicroWorld-eScan | Trojan.GenericKD.39628153 |
| Ad-Aware | Trojan.GenericKD.39628153 |
| DrWeb | Exploit.CVE-2018-0798.4 |
| McAfee-GW-Edition | RDN/exploit-ole2.gen |
| FireEye | Trojan.GenericKD.39628153 |
| Emsisoft | Trojan.GenericKD.39628153 (B) |
| GData | Trojan.GenericKD.39628153 |
| Avira | EXP/W97M.Agent.avuvd |
| MAX | malware (ai score=84) |
| ViRobot | XLS.Z.CVE-2018-0798.10361 |
| ZoneAlarm | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |
| AhnLab-V3 | OLE/Cve-2018-0798.Gen |
| TACHYON | Suspicious/XOX.CVE-2018-0798 |
| Fortinet | MSExcel/CVE_2017_11882!exploit |
| AVG | Other:Malware-gen [Trj] |
| ALYac | Trojan.Downloader.XLS.Gen |
| Arcabit | Trojan.Generic.D25CAD79 |
| Cyren | CVE180802 |
| Detected | |
| Kingsoft | Macro.Excel.Generic.jm.(kcloud) |
| Microsoft | Exploit:O97M/CVE-2018-0798.KA!MTB |
| Sangfor | Exploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg |
| Tencent | Office.Exploit.Generic.Pdvz |
| TrendMicro | Trojan.X97M.CVE201711882.XQUOPEB |
| TrendMicro-HouseCall | Trojan.X97M.CVE201711882.XQUOPEB |
| VIPRE | Trojan.GenericKD.39628153 |
| ZoneAlarm | HEUR:Exploit.MSOffice.Generic |
| ALYac | Trojan.Generic.39060736 |
| Antiy-AVL | Trojan[Exploit]/MSOffice.CVE-2018-0798 |
| Arcabit | Trojan.Generic.D2540500 |
| BitDefender | Trojan.Generic.39060736 |
| CTX | xlsx.trojan.office |
| ESET-NOD32 | Win32/Exploit.CVE-2018-0798.A trojan |
| Emsisoft | Trojan.Generic.39060736 (B) |
| GData | Trojan.Generic.39060736 |
| Ikarus | Exploit.CVE-2018-0798 |
| Kingsoft | Win32.Troj.Undef.a |
| Lionic | Trojan.MSExcel.Office.4!c |
| MicroWorld-eScan | Trojan.Generic.39060736 |
| Skyhigh | Artemis!Trojan |
| Tencent | Office.Exploit.Generic.Bnhl |
| VIPRE | Trojan.Generic.39060736 |
| Varist | CVE180802 |
| alibabacloud | Exploit:MSOffice/ZxxZDownloader.9944376 |