840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e
Classification: Malicious
840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e is a malicious file sample. Linked to Bitter activity. Detected by 30 antivirus engines.
Detection summary
- 30 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BITTER (G1002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitter | MalwareBazaar Abuse.ch | 2022-05-13 08:17:26 | 2022-05-13 08:17:26 | malicious-activity | G1002 BITTER |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-05-13 08:17:26 | 2022-05-13 08:17:26 | malicious-activity |
Sample information
- Filenames
- 840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e
- File type
- application/CDFV2
- MD5
c1b74e52b662bf071e1a2e8ccd7d578a- SHA-1
189ee2f56f50cbc6c446124fd45b3e247245ecdc- SHA-256
840e37db659cb1cf750c8bcc3e928b22173fdc3cb79d888502e30452be17c04e- First indexed
- 2022-05-13 09:15:04
- Last updated
- 2026-04-02 16:20:33
Antivirus detections
| Engine | Detection |
|---|---|
| DrWeb | Exploit.CVE-2018-0798.4 |
| ClamAV | Ole2.Exploit.ZxxZDownloader-9944376-0 |
| McAfee | RDN/exploit-ole2.gen |
| ESET-NOD32 | Win32/Exploit.CVE-2018-0798.A |
| Kaspersky | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |
| McAfee-GW-Edition | RDN/exploit-ole2.gen |
| ZoneAlarm | HEUR:Exploit.MSOffice.CVE-2018-0802.gen |
| AhnLab-V3 | OLE/Cve-2018-0798.Gen |
| TACHYON | Trojan-Exploit/W97.CVE-2018-0798 |
| ALYac | Exploit.CVE-2018-0798 |
| AVG | Other:Malware-gen [Trj] |
| Antiy-AVL | Trojan[Exploit]/MSOffice.CVE-2018-0802 |
| Arcabit | Trojan.Generic.D2EBF51F |
| Avast | Other:Malware-gen [Trj] |
| BitDefender | Trojan.GenericKD.49018143 |
| CTX | unknown.exploit-kit.office |
| Emsisoft | Trojan.GenericKD.49018143 (B) |
| GData | Trojan.GenericKD.49018143 |
| Detected | |
| Ikarus | Exploit.CVE-2018-0798 |
| Lionic | Trojan.MSWord.CVE-2018-0802.3!c |
| MicroWorld-eScan | Trojan.GenericKD.49018143 |
| Sangfor | Exploit.Office/CVE-2018-0798.APT-BITTER.ulgcyg |
| Symantec | Trojan.Gen.NPE |
| Tencent | Office.Exploit.Cve-2018-0802.Iajl |
| TrendMicro | EXPL_CVE1711882 |
| TrendMicro-HouseCall | EXPL_CVE1711882 |
| VIPRE | Trojan.GenericKD.49018143 |
| Varist | ABTrojan.NMYI- |
| alibabacloud | Exploit:MSOffice/ZxxZDownloader.9944376 |