🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1322ed18efc7d1ee0b7afe13f5720982e694b93c5648d6e2da8bb5a64cdc2ac3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1322ed18efc7d1ee0b7afe13f5720982e694b93c5648d6e2da8bb5a64cdc2ac3
SHA3-384 hash: b7d872ee78fc53fdbb6f960f14a3fe87c913695ecb4df1dbf84221cf241ef9ffebc5e19d767788aaf66f1aa073d472c6
SHA1 hash: e6ad703d02c9bffe0be0fc5aa5ed6ff93f908386
MD5 hash: ba3803d7c861ce6c62ef718173d06115
humanhash: stairway-mockingbird-texas-eight
File name:Document_09_13_622.zip
Download: download sample
Signature IcedID
File size:11'639 bytes
First seen:2023-09-13 19:47:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:6EC02cgQL0ON7AoAx+7AuhLzK/tbU9OAG7WODOWY1XRKLKiLT6Y:Flrg+08UoAxSz4tbUrGqwOntUeY
TLSH T1CB32B18268414250C56294F1CB5B8AAB87A723732BDCCC5E5BAD118E0CBFDF7D63046A
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter k3dg3___
Tags:1638996626 IcedID minutozhart zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Document_09_13_622.js
File size:47'475 bytes
SHA256 hash: ae712346e43b8461dc3481b3eaea434da058601c5323a7a6e7982a84bd3405db
MD5 hash: d333e5162c0beb9361f650ed35012938
MIME type:text/plain
Signature IcedID
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive lolbin lolbin obfuscated replace rundll32
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2023-09-13 19:48:04 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
11 of 24 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

zip 1322ed18efc7d1ee0b7afe13f5720982e694b93c5648d6e2da8bb5a64cdc2ac3

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments