🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 274ff7a41a6af130f6342b4625ab139c7077702e59cd0d5fc375f404a918b6be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 274ff7a41a6af130f6342b4625ab139c7077702e59cd0d5fc375f404a918b6be
SHA3-384 hash: a32fb1f588832b655dbbb3945809bd014a50010832dc98a6517345f838bf58d7249a3d1054521c58c43a6255565f1596
SHA1 hash: 19511d280ef422d6aa509e603a88160f06dd6e4e
MD5 hash: 658f14c5d83de5e5fee5f5ae00087139
humanhash: mike-pennsylvania-november-zulu
File name:loader_p1_dll_64_n1_x64_inf.dll77.dll
Download: download sample
Signature IcedID
File size:381'440 bytes
First seen:2023-03-14 23:37:16 UTC
Last seen:2023-03-15 01:31:12 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 46c09ac363e8f98a61dc89538208d875 (1 x IcedID)
ssdeep 6144:wI+QWLzCll9xQXnJ2740Za/Q6hJFl/q+LT54w:wP1zCb9xQXnJCfx6hPdK
TLSH T15D844ADBF6506097EA67403C8663573BF2B1306F0362A6EB076442559F23BD6363B2D8
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter proxylife
Tags:exe IcedID

Intelligence


File Origin
# of uploads :
2
# of downloads :
303
Origin country :
IS IS
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Contract_March_14#83.html
Verdict:
Malicious activity
Analysis date:
2023-03-14 20:04:39 UTC
Tags:
loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
icedid
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2023-03-14 20:36:58 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
274ff7a41a6af130f6342b4625ab139c7077702e59cd0d5fc375f404a918b6be
MD5 hash:
658f14c5d83de5e5fee5f5ae00087139
SHA1 hash:
19511d280ef422d6aa509e603a88160f06dd6e4e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

Executable exe 274ff7a41a6af130f6342b4625ab139c7077702e59cd0d5fc375f404a918b6be

(this sample)

  
Delivery method
Distributed via web download

Comments