🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0fbe0024554ee9aee8d6c5814bf16e33d9a90425ea7230ac72ae7f4e2df73938. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0fbe0024554ee9aee8d6c5814bf16e33d9a90425ea7230ac72ae7f4e2df73938
SHA3-384 hash: db66cec0eea77a9313fe1834be65592f3f2c64f33dc2c69ff4f44cd30c863650eb7a8c53237bb91bca5dceb0a8c2d299
SHA1 hash: 9c941e42f6065962ce6d0035d2cf8d3d9aeb44d3
MD5 hash: 95ac7f1da2334fa9d695664c5b8be3f2
humanhash: sixteen-nitrogen-golf-early
File name:Paid_Offer_268_Jan-19.pdf
Download: download sample
Signature IcedID
File size:139'496 bytes
First seen:2023-01-20 00:32:15 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:k59bPadhK2by1Qt0buXiOiJxqeynSFyYVjTNPe2Nk6FL0E+FuA9Y8mmS3G:JG40buSOibqeUAyoTRe81LfamG
TLSH T161D31207E21BA960DF2E40BA5704105FFEF7B44605EDA5B1A3EB0496877E4BBCD14B88
Reporter proxylife
Tags:3108046779 IcedID pdf ragpewleaK

Intelligence


File Origin
# of uploads :
1
# of downloads :
437
Origin country :
IE IE
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
2/10
Score Malicious:
3%
Score Benign:
97%
Result
Threat name:
Qbot Downloader
Detection:
malicious
Classification:
spre.troj
Score:
52 / 100
Signature
C2 URLs / IPs found in malware configuration
Yara detected Qbot Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 787926 Sample: Paid_Offer_268_Jan-19.pdf Startdate: 20/01/2023 Architecture: WINDOWS Score: 52 36 Yara detected Qbot Downloader 2->36 38 C2 URLs / IPs found in malware configuration 2->38 8 chrome.exe 18 8 2->8         started        11 AcroRd32.exe 15 42 2->11         started        13 chrome.exe 2->13         started        process3 dnsIp4 34 239.255.255.250 unknown Reserved 8->34 15 unarchiver.exe 4 8->15         started        17 chrome.exe 8->17         started        20 RdrCEF.exe 62 11->20         started        process5 dnsIp6 22 7za.exe 2 15->22         started        26 accounts.google.com 142.250.180.141, 443, 49685 GOOGLEUS United States 17->26 28 www.google.com 142.251.209.4, 443, 49694, 49709 GOOGLEUS United States 17->28 32 3 other IPs or domains 17->32 30 192.168.2.1 unknown unknown 20->30 process7 process8 24 conhost.exe 22->24         started       
Threat name:
Document-PDF.Trojan.IcedID
Status:
Malicious
First seen:
2023-01-20 00:33:07 UTC
File Type:
Document
Extracted files:
2
AV detection:
9 of 26 (34.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments