840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e

Classification: Malicious

840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e is a malicious file sample. Linked to Bitter activity. Detected by 30 antivirus engines.

Detection summary

  • 30 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: BITTER (G1002)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Bitter MalwareBazaar Abuse.ch 2022-05-13 08:17:26 2022-05-13 08:17:26 malicious-activity G1002 BITTER
Generic.Malware MalwareBazaar Abuse.ch 2022-05-13 08:17:26 2022-05-13 08:17:26 malicious-activity

Sample information

Filenames
840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e
File type
application/CDFV2
MD5
c1b74e52b662bf071e1a2e8ccd7d578a
SHA-1
189ee2f56f50cbc6c446124fd45b3e247245ecdc
SHA-256
840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e
First indexed
2022-05-13 09:15:04
Last updated
2026-04-02 16:20:33

Antivirus detections

EngineDetection
DrWebExploit.CVE-2018-0798.4
ClamAVOle2.Exploit.ZxxZDownloader-9944376-0
McAfeeRDN/exploit-ole2.gen
ESET-NOD32Win32/Exploit.CVE-2018-0798.A
KasperskyHEUR:Exploit.MSOffice.CVE-2018-0802.gen
McAfee-GW-EditionRDN/exploit-ole2.gen
ZoneAlarmHEUR:Exploit.MSOffice.CVE-2018-0802.gen
AhnLab-V3OLE/Cve-2018-0798.Gen
TACHYONTrojan-Exploit/W97.CVE-2018-0798
ALYacExploit.CVE-2018-0798
AVGOther:Malware-gen [Trj]
Antiy-AVLTrojan[Exploit]/MSOffice.CVE-2018-0802
ArcabitTrojan.Generic.D2EBF51F
AvastOther:Malware-gen [Trj]
BitDefenderTrojan.GenericKD.49018143
CTXunknown.exploit-kit.office
EmsisoftTrojan.GenericKD.49018143 (B)
GDataTrojan.GenericKD.49018143
GoogleDetected
IkarusExploit.CVE-2018-0798
LionicTrojan.MSWord.CVE-2018-0802.3!c
MicroWorld-eScanTrojan.GenericKD.49018143
SangforExploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg
SymantecTrojan.Gen.NPE
TencentOffice.Exploit.Cve-2018-0802.Iajl
TrendMicroEXPL_CVE1711882
TrendMicro-HouseCallEXPL_CVE1711882
VIPRETrojan.GenericKD.49018143
VaristABTrojan.NMYI-
alibabacloudExploit:MSOffice/ZxxZDownloader.9944376