🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 096a00f5d3c3d58a83407ebd7ffec898c0522c96eaf44bc79ea20bd0e6f53b2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 096a00f5d3c3d58a83407ebd7ffec898c0522c96eaf44bc79ea20bd0e6f53b2a
SHA3-384 hash: dda7b5d0c9aae8c0f3893b0b516bf971bdc70bee5975b01528baedda9237f95f85b7acdf151dc8ef7512648d8c7c3762
SHA1 hash: a60b98248a1324d79edfb4f192437e69626eb41a
MD5 hash: 2ddab6d6d12e29881d94a0bed351d200
humanhash: tango-speaker-robert-uncle
File name:convert-pdf-429.zip
Download: download sample
Signature IcedID
File size:11'422 bytes
First seen:2023-09-13 10:03:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 975
ssdeep 192:7zm+Zswfc4Xb415D6Dr1gOBGDvGGVVY6voimMFNpjpxGXp/+Ak5QnSm4eI/lGDMv:Xm+vRr41J6O4GqOY6Qyy/5qQn9qkodNP
TLSH T1EE32C0C794C372088F1797F4AD8C90706380DDA2B1EC652221BB164127C845F9F9A97F
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter Mangusta
Tags:909843654 IcedID pw-975 vocesdelatinoamerica-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
176
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:convert-pdf-429.js
File size:45'201 bytes
SHA256 hash: a40c6e2adf1d5e146658498c816a1cfada18dc6a2b9503f90627fae4b32fc1a1
MD5 hash: 73e7464319bc7e8eb307b9259fa70fd2
MIME type:text/plain
Signature IcedID
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:909843654 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Downloads MZ/PE file
IcedID, BokBot
Malware Config
C2 Extraction:
restohalto.site
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments