🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 19c6557ae51b7322ad35b35cf4729fc98521a1b99b0f9bb14d39defe4e2a0e09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 19c6557ae51b7322ad35b35cf4729fc98521a1b99b0f9bb14d39defe4e2a0e09
SHA3-384 hash: bd8e64c4ab554c6ef222f689abc346ce3e94f887b3a93b72a4b66941783bcb28c1928c737f632131c5538b5c7a438131
SHA1 hash: 282a20df6eff21b58c480b28db1d04ab632d3c25
MD5 hash: 0b7b3668c7c6a12cdc41c45dc5ecf28b
humanhash: hotel-oregon-alanine-earth
File name:Scan_01-20.lnk
Download: download sample
Signature IcedID
File size:1'978 bytes
First seen:2023-01-26 23:37:41 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/octet-stream
ssdeep 12:8x4erbelFfhJiayf1ymfVSCUfefqbcPl+Uc7c3Prfq:8x9MfhJ61yZCpf8cPl+/Q/rf
TLSH T13441E96413DD1A48C3769D797C7CB1044A77B8260E31C669068852C18F54728ED7A777
Reporter atomiczsec
Tags:IcedID lnk

Intelligence


File Origin
# of uploads :
1
# of downloads :
164
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Windows shortcut file (LNK) starts blacklisted processes
Behaviour
Behavior Graph:
Threat name:
Shortcut.Trojan.IcedIdLNK
Status:
Malicious
First seen:
2023-01-20 15:10:47 UTC
File Type:
Binary
AV detection:
17 of 39 (43.59%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments