5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725

Classification: Malicious

5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725 is a malicious file sample. Linked to Bitter activity. Detected by 34 antivirus engines.

Detection summary

  • 34 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: BITTER (G1002)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Bitter MalwareBazaar Abuse.ch 2022-05-13 07:56:58 2022-05-13 07:56:58 malicious-activity G1002 BITTER
Generic.Malware MalwareBazaar Abuse.ch 2022-05-13 07:56:58 2022-05-13 07:56:58 malicious-activity

Sample information

Filenames
5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725
File type
text/plain
MD5
6f538874524c8da38fd1a93d3efe726a
SHA-1
f4e370f582c44db13ef9f539074a591f88ca973d
SHA-256
5aa0d7817105bea29bf56ccf62db63e2217719d192e1f7f66ae55922fb4c3725
First indexed
2022-05-13 09:15:07
Last updated
2026-09-03 04:01:20

Antivirus detections

EngineDetection
SangforMalware.Generic-RTF.Save.b35abd92
ESET-NOD32Win32/Exploit.CVE-2017-11882.CO
TrendMicro-HouseCallPossible_SMBCVE20170199
NANO-AntivirusExploit.Rtf.Heuristic-rtf.dinbqn
DrWebExploit.CVE-2018-0798.4
TrendMicroHEUR_RTFMALFORM
IkarusExploit.CVE-2017-11882
AhnLab-V3OLE/Cve-2018-0798.Gen
ZonerProbably Heur.RTFBadHeader
RisingExploit.CVE-2017-11882!1.D440 (CLASSIC)
TACHYONTrojan-Exploit/RTF.CVE-2018-0798
ALYacExploit.CVE-2017-11882
AVGOther:Malware-gen [Trj]
Ad-AwareTrojan.GenericKD.48296514
Antiy-AVLTrojan/Generic.ASSuf.31CB4
AvastOther:Malware-gen [Trj]
BitDefenderTrojan.GenericKD.48296514
ClamAVOle2.Exploit.ZxxZDownloader-9944376-0
CyrenCVE1711882
EmsisoftTrojan.GenericKD.48296514 (B)
FireEyeTrojan.GenericKD.48296514
GDataTrojan.GenericKD.48296514
GoogleDetected
KasperskyHEUR:Exploit.MSOffice.Generic
LionicTrojan.MSOffice.Generic.4!c
MAXmalware (ai score=82)
McAfee-GW-EditionBehavesLike.Trojan.mv
MicroWorld-eScanTrojan.GenericKD.48296514
MicrosoftExploit:O97M/CVE-2017-11882!MSR
SangforExploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg
SymantecTrojan.Gen.NPE
TencentOffice.Exploit.Generic.Fajl
VIPRETrojan.GenericKD.48296514
ZoneAlarmHEUR:Exploit.MSOffice.CVE-2018-0802.gen