471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8

Classification: Malicious

471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8 is a malicious file sample. Linked to Bitter activity. Detected by 54 antivirus engines.

Detection summary

  • 54 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: BITTER (G1002)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Bitter MalwareBazaar Abuse.ch 2022-05-13 08:17:44 2022-05-13 08:17:44 malicious-activity G1002 BITTER
Generic.Malware MalwareBazaar Abuse.ch 2022-05-13 08:17:44 2022-05-13 08:17:44 malicious-activity

Sample information

Filenames
471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8
File type
application/octet-stream
MD5
b90f8e14181f04d2b95575a4ad8fa0b7
SHA-1
dbfc24ba97158d97082be5180bbf20bbbb3d0761
SHA-256
471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8
First indexed
2022-05-13 09:15:03
Last updated
2026-07-10 00:42:07

Antivirus detections

EngineDetection
LionicTrojan.Multi.Generic.4!c
ClamAVOle2.Exploit.ZxxZDownloader-9944376-0
McAfeeRDN/exploit-ole2.gen
AlibabaTrojan:Win32/MalDoc.ali1000146
SymantecTrojan.Gen.NPE
ESET-NOD32Win32/Exploit.CVE-2018-0798.A
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.39628153
MicroWorld-eScanTrojan.GenericKD.39628153
Ad-AwareTrojan.GenericKD.39628153
DrWebExploit.CVE-2018-0798.4
McAfee-GW-EditionRDN/exploit-ole2.gen
FireEyeTrojan.GenericKD.39628153
EmsisoftTrojan.GenericKD.39628153 (B)
GDataTrojan.GenericKD.39628153
AviraEXP/W97M.Agent.avuvd
MAXmalware (ai score=84)
ViRobotXLS.Z.CVE-2018-0798.10361
ZoneAlarmHEUR:Exploit.MSOffice.CVE-2018-0802.gen
AhnLab-V3OLE/Cve-2018-0798.Gen
TACHYONSuspicious/XOX.CVE-2018-0798
FortinetMSExcel/CVE_2017_11882!exploit
AVGOther:Malware-gen [Trj]
ALYacTrojan.Downloader.XLS.Gen
ArcabitTrojan.Generic.D25CAD79
CyrenCVE180802
GoogleDetected
KingsoftMacro.Excel.Generic.jm.(kcloud)
MicrosoftExploit:O97M/CVE-2018-0798.KA!MTB
SangforExploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg
TencentOffice.Exploit.Generic.Pdvz
TrendMicroTrojan.X97M.CVE201711882.XQUOPEB
TrendMicro-HouseCallTrojan.X97M.CVE201711882.XQUOPEB
VIPRETrojan.GenericKD.39628153
ZoneAlarmHEUR:Exploit.MSOffice.Generic
ALYacTrojan.Generic.39060736
Antiy-AVLTrojan[Exploit]/MSOffice.CVE-2018-0798
ArcabitTrojan.Generic.D2540500
BitDefenderTrojan.Generic.39060736
CTXxlsx.trojan.office
ESET-NOD32Win32/Exploit.CVE-2018-0798.A trojan
EmsisoftTrojan.Generic.39060736 (B)
GDataTrojan.Generic.39060736
IkarusExploit.CVE-2018-0798
KingsoftWin32.Troj.Undef.a
LionicTrojan.MSExcel.Office.4!c
MicroWorld-eScanTrojan.Generic.39060736
SkyhighArtemis!Trojan
TencentOffice.Exploit.Generic.Bnhl
VIPRETrojan.Generic.39060736
VaristCVE180802
alibabacloudExploit:MSOffice/ZxxZDownloader.9944376