5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725
Classification: Malicious
5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725 is a malicious file sample. Linked to Bitter activity. Detected by 34 antivirus engines.
Detection summary
- 34 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BITTER (G1002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitter | MalwareBazaar Abuse.ch | 2022-05-13 07:56:58 | 2022-05-13 07:56:58 | malicious-activity | G1002 BITTER |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-05-13 07:56:58 | 2022-05-13 07:56:58 | malicious-activity |
Sample information
- Filenames
- 5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725
- File type
- text/plain
- MD5
6f538874524c8da38fd1a93d3efe726a- SHA-1
f4e370f582c44db13ef9f539074a591f88ca973d- SHA-256
5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725- First indexed
- 2022-05-13 09:15:07
- Last updated
- 2026-09-03 04:01:20
Antivirus detections
| Engine | Detection |
|---|---|
| Sangfor | Malware.Generic-RTF.Save.b35abd92 |
| ESET-NOD32 | Win32/Exploit.CVE-2017-11882.CO |
| TrendMicro-HouseCall | Possible_SMBCVE20170199 |
| NANO-Antivirus | Exploit.Rtf.Heuristic-rtf.dinbqn |
| DrWeb | Exploit.CVE-2018-0798.4 |
| TrendMicro | HEUR_RTFMALFORM |
| Ikarus | Exploit.CVE-2017-11882 |
| AhnLab-V3 | OLE/Cve-2018-0798.Gen |
| Zoner | Probably Heur.RTFBadHeader |
| Rising | Exploit.CVE-2017-11882!1.D440 (CLASSIC) |
| TACHYON | Trojan-Exploit/RTF.CVE-2018-0798 |
| ALYac | Exploit.CVE-2017-11882 |
| AVG | Other:Malware-gen [Trj] |
| Ad-Aware | Trojan.GenericKD.48296514 |
| Antiy-AVL | Trojan/Generic.ASSuf.31CB4 |
| Avast | Other:Malware-gen [Trj] |
| BitDefender | Trojan.GenericKD.48296514 |
| ClamAV | Ole2.Exploit.ZxxZDownloader-9944376-0 |
| Cyren | CVE1711882 |
| Emsisoft | Trojan.GenericKD.48296514 (B) |
| FireEye | Trojan.GenericKD.48296514 |
| GData | Trojan.GenericKD.48296514 |
| Detected | |
| Kaspersky | HEUR:Exploit.MSOffice.Generic |
| Lionic | Trojan.MSOffice.Generic.4!c |
| MAX | malware (ai score=82) |
| McAfee-GW-Edition | BehavesLike.Trojan.mv |
| MicroWorld-eScan | Trojan.GenericKD.48296514 |
| Microsoft | Exploit:O97M/CVE-2017-11882!MSR |
| Sangfor | Exploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg |
| Symantec | Trojan.Gen.NPE |
| Tencent | Office.Exploit.Generic.Fajl |
| VIPRE | Trojan.GenericKD.48296514 |
| ZoneAlarm | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |