7f946eca44b547e643b57342b756ce1af5b3a0de1ce0b22eb9ac2b4e7e10e521
Classification: Malicious
7f946eca44b547e643b57342b756ce1af5b3a0de1ce0b22eb9ac2b4e7e10e521 is a malicious file sample. Linked to Bitter activity. Detected by 42 antivirus engines.
Detection summary
- 42 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BITTER (G1002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitter | MalwareBazaar Abuse.ch | 2022-05-13 08:17:23 | 2022-05-13 08:17:23 | malicious-activity | G1002 BITTER |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-05-13 08:17:23 | 2022-05-13 08:17:23 | malicious-activity |
Sample information
- Filenames
- 7f946eca44b547e643b57342b756ce1af5b3a0de1ce0b22eb9ac2b4e7e10e521
- File type
- application/vnd.openxmlformats-officedocument.presentationml.presentation
- MD5
5b039bedad9d067503016eecdf7b0809- SHA-1
69a605808bacd35d8d49b6c263de7f417ee5c0a9- SHA-256
7f946eca44b547e643b57342b756ce1af5b3a0de1ce0b22eb9ac2b4e7e10e521- First indexed
- 2022-05-13 09:15:04
- Last updated
- 2025-11-12 14:17:05
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.MSOffice.CVE-2018-0802.3!c |
| MicroWorld-eScan | Trojan.Generic.31285846 |
| FireEye | Trojan.Generic.31285846 |
| Alibaba | Exploit:Office/CVE-2018-0802.c3039e99 |
| Symantec | Trojan.Gen.NPE |
| ESET-NOD32 | a variant of Generik.LLKKOUN |
| TrendMicro-HouseCall | TROJ_FRS.0NA103ED22 |
| Avast | Other:Malware-gen [Trj] |
| ClamAV | Ole2.Exploit.ZxxZDownloader-9944376-0 |
| Kaspersky | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |
| BitDefender | Trojan.Generic.31285846 |
| Tencent | Office.Exploit.Cve-2018-0802.Suxn |
| Ad-Aware | Trojan.Generic.31285846 |
| TACHYON | Suspicious/POX.CVE-2018-0798 |
| Emsisoft | Trojan.Generic.31285846 (B) |
| DrWeb | Exploit.CVE-2018-0798.4 |
| TrendMicro | TROJ_FRS.0NA103ED22 |
| McAfee-GW-Edition | RDN/exploit-ole2.gen |
| Ikarus | Trojan.SuspectCRC |
| ViRobot | DOC.Z.CVE-2018-0798.6656.G |
| ZoneAlarm | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |
| GData | Trojan.Generic.31285846 |
| AhnLab-V3 | OLE/Cve-2018-0798.Gen |
| McAfee | RDN/exploit-ole2.gen |
| MAX | malware (ai score=85) |
| AVG | Other:Malware-gen [Trj] |
| ALYac | Exploit.CVE-2018-0802 |
| Antiy-AVL | Trojan[Exploit]/MSOffice.CVE-2018-0802 |
| Arcabit | Trojan.Generic.D2EBF51F [many] |
| BitDefender | Trojan.GenericKD.49018143 |
| CTX | pptx.exploit-kit.office |
| Emsisoft | Trojan.GenericKD.49018143 (B) |
| GData | Trojan.GenericKD.39675675 |
| Detected | |
| Ikarus | Exploit.CVE-2018-0798 |
| Lionic | Trojan.MSPPoint.Office.3!c |
| MicroWorld-eScan | Trojan.GenericKD.39675675 |
| Sangfor | Exploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg |
| Tencent | Office.Exploit.Cve-2018-0802.Cujl |
| VIPRE | Trojan.GenericKD.49018143 |
| Varist | ABTrojan.ZQKP- |
| alibabacloud | Exploit:MSOffice/ZxxZDownloader.9944376 |