🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26509fa876a07966824bed8e5b0a6e0626b37d68355871fac49b2fa636d7fe6e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 26509fa876a07966824bed8e5b0a6e0626b37d68355871fac49b2fa636d7fe6e
SHA3-384 hash: 95e1d192e564bbc33b5735b71c51118e09c8a2a1fd6494e2236da47c992d69873d2190f46797dcafd132599f67504f32
SHA1 hash: 329195d5123e5d1b087dccd408cb7a7b2cf78b62
MD5 hash: 2ed4c52849a4936601057af9fdd3b761
humanhash: mexico-moon-iowa-oregon
File name:JlCfqHageWaCS_2OWwpuBiazfWg1WHH6xJsvpjbX-m4.bin
Download: download sample
Signature IcedID
File size:93'108 bytes
First seen:2023-03-17 18:31:07 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:E9/61mTBPnwaXEpbg0vn0l7GF5MCI1MDAKJDojPI1flNBOheDXLG8lqrYm4:8/61mFnr8MurIiDAKJDQiqheDC4
TLSH T1B29312895078BA7CDC33413987C651A4A2CBF1DBB8D1A8A73FEC5C2992834D0877B592
Reporter k3dg3___
Tags:946873669 IcedID pdf


Avatar
k3dg3
C2: umoxlopator.com
ProjectID: 946873669

Intelligence


File Origin
# of uploads :
1
# of downloads :
470
Origin country :
US US
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
2%
Score Benign:
98%
Result
Threat name:
Detection:
malicious
Classification:
bank.troj.expl.evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Contains functionality to detect hardware virtualization (CPUID execution measurement)
Downloads suspicious files via Chrome
Encrypted powershell cmdline option found
Malicious encrypted Powershell command line found
Malicious sample detected (through community Yara rule)
PowerShell case anomaly found
Powershell drops PE file
Sigma detected: Execute DLL with spoofed extension
Snort IDS alert for network traffic
Suspicious execution chain found
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to detect virtualization through RDTSC time measurements
Wscript starts Powershell (via cmd or directly)
Yara detected Html Dropper
Yara detected IcedID
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 829056 Sample: JlCfqHageWaCS_2OWwpuBiazfWg... Startdate: 17/03/2023 Architecture: WINDOWS Score: 100 85 Snort IDS alert for network traffic 2->85 87 Malicious sample detected (through community Yara rule) 2->87 89 Yara detected Html Dropper 2->89 91 6 other signatures 2->91 12 chrome.exe 18 9 2->12         started        16 AcroRd32.exe 15 42 2->16         started        18 chrome.exe 2->18         started        process3 dnsIp4 73 192.168.2.6 unknown unknown 12->73 75 192.168.2.7 unknown unknown 12->75 77 239.255.255.250 unknown Reserved 12->77 57 e91a1b72-da9d-46aa-9f26-e87cc972f1c7.tmp, HTML 12->57 dropped 59 C:\Users\user\...\Unpaid_March_17.zip (copy), Zip 12->59 dropped 20 unarchiver.exe 4 12->20         started        22 chrome.exe 12->22         started        25 RdrCEF.exe 60 16->25         started        file5 process6 dnsIp7 27 cmd.exe 2 2 20->27         started        30 7za.exe 2 20->30         started        63 umoxlopator.com 22->63 65 accounts.google.com 142.250.180.173, 443, 49697 GOOGLEUS United States 22->65 69 4 other IPs or domains 22->69 67 192.168.2.1 unknown unknown 25->67 process8 signatures9 107 Malicious encrypted Powershell command line found 27->107 109 Suspicious powershell command line found 27->109 111 Wscript starts Powershell (via cmd or directly) 27->111 113 3 other signatures 27->113 32 wscript.exe 1 27->32         started        35 conhost.exe 27->35         started        37 conhost.exe 30->37         started        process10 signatures11 79 Malicious encrypted Powershell command line found 32->79 81 Wscript starts Powershell (via cmd or directly) 32->81 83 PowerShell case anomaly found 32->83 39 cmd.exe 1 32->39         started        process12 signatures13 99 Malicious encrypted Powershell command line found 39->99 101 Suspicious powershell command line found 39->101 103 Wscript starts Powershell (via cmd or directly) 39->103 105 2 other signatures 39->105 42 powershell.exe 15 17 39->42         started        47 conhost.exe 39->47         started        process14 dnsIp15 71 dexteroa.top 185.173.38.133, 49822, 49824, 80 ECO-ASRU Russian Federation 42->71 55 C:\Users\user\AppData\Local\Temp\zpTIxn.dat, PE32+ 42->55 dropped 115 Powershell drops PE file 42->115 49 rundll32.exe 42->49         started        file16 signatures17 process18 process19 51 rundll32.exe 49->51         started        dnsIp20 61 umoxlopator.com 80.78.24.30, 49826, 49829, 49831 CYBERDYNELR Cyprus 51->61 93 System process connects to network (likely due to code injection or exploit) 51->93 95 Contains functionality to detect hardware virtualization (CPUID execution measurement) 51->95 97 Tries to detect virtualization through RDTSC time measurements 51->97 signatures21
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

pdf 26509fa876a07966824bed8e5b0a6e0626b37d68355871fac49b2fa636d7fe6e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments