9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e
Classification: Malicious
9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e is a malicious file sample. Linked to Bitter activity. Detected by 27 antivirus engines.
Detection summary
- 27 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BITTER (G1002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitter | MalwareBazaar Abuse.ch | 2022-05-13 09:30:53 | 2022-05-13 09:30:53 | malicious-activity | G1002 BITTER |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-05-13 09:30:53 | 2022-05-13 09:30:53 | malicious-activity |
Sample information
- Filenames
- 9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e
- File type
- text/plain
- MD5
bf1a905e11f4d44de8bd2e0a6f383ed5- SHA-1
a07b22ac47f0e304ae2bbc070de371dd78e9daa2- SHA-256
9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e- First indexed
- 2022-05-13 11:15:08
- Last updated
- 2026-04-26 18:11:49
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.MSOffice.Generic.4!c |
| DrWeb | Exploit.CVE-2018-0798.4 |
| ALYac | Exploit.CVE-2017-11882 |
| Sangfor | Malware.Generic-RTF.Save.b35abd92 |
| Symantec | Trojan.Mdropper |
| ESET-NOD32 | Win32/Exploit.CVE-2017-11882.CO |
| Avast | Other:Malware-gen [Trj] |
| Cynet | Malicious (score: 99) |
| BitDefender | Trojan.GenericKD.47820814 |
| NANO-Antivirus | Exploit.Rtf.Heuristic-rtf.dinbqn |
| MicroWorld-eScan | Trojan.GenericKD.47820814 |
| Tencent | Win32.Trojan.Generic.Pgms |
| Ad-Aware | Trojan.GenericKD.47820814 |
| Emsisoft | Trojan.GenericKD.47820814 (B) |
| TrendMicro | HEUR_RTFMALFORM |
| FireEye | Trojan.GenericKD.47820814 |
| GData | Trojan.GenericKD.47820814 |
| Avira | EXP/YAV.Minerva.ynlta |
| MAX | malware (ai score=88) |
| Arcabit | Trojan.Generic.D2D9B00E |
| Microsoft | Exploit:O97M/CVE-2017-11882.SM!MTB |
| AhnLab-V3 | OLE/Cve-2018-0798.Gen |
| TACHYON | Trojan-Exploit/RTF.CVE-2018-0798 |
| Zoner | Probably Heur.RTFBadHeader |
| Rising | Exploit.CVE-2017-11882!1.D440 (CLASSIC) |
| Ikarus | Exploit.CVE-2017-11882 |
| AVG | Other:Malware-gen [Trj] |