🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ac7da9a2d7d4de43bc05c869a0ab9c397a929def4693e21fda87850fc327bf3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2ac7da9a2d7d4de43bc05c869a0ab9c397a929def4693e21fda87850fc327bf3
SHA3-384 hash: 74290c4e15f78ea03f8f8ec4faf736e1019bdd70180f53523cdda01a9dd682fe65e3926b3bfa03df2477e245ab361bea
SHA1 hash: 7fed0b557c5fc8d4c61820affcb17a72c65c3484
MD5 hash: afd56eb241a34afd74813a114b6d875c
humanhash: glucose-snake-football-eight
File name:Setup_Win_15-02-2023_18-31-42.zip
Download: download sample
Signature IcedID
File size:829'320 bytes
First seen:2023-02-15 18:38:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:M/gkEpZGKkxJJJ6lu1cCoUYJQXRyAIUufs+tgOz8OYbq:MFEpZdkxJ2lgCU1RJIUXGNL
TLSH T18E05012BF0387631E48DC5B01A7D00782776153C175AFBCB8DF2814ABF95AE43B21A66
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter malware_traffic
Tags:BokBot file-pumped IcedID inflated_exe zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
190
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup_Win_15-02-2023_18-31-39.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:742'712'472 bytes
SHA256 hash: 17ecd92abf803b1d922eb945205e0e5d65a9de44e2547325fb658c13d3f8337d
MD5 hash: 732e9dd4f59940c7305b42be3bf6dee6
De-pumped file size:742'701'568 bytes (Vs. original size of 742'712'472 bytes)
De-pumped SHA256 hash: fdb5a70ff85e4ee153eca0a8cce8ab204d900bb588d5455f9eed9798fd2fda00
De-pumped MD5 hash: f7177a27428a489c87815f49911a4c9b
MIME type:application/x-dosexec
Signature IcedID
Vendor Threat Intelligence
Gathering data
Threat name:
Archive.Trojan.Hulk
Status:
Malicious
First seen:
2023-02-15 19:12:36 UTC
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:2076641214 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
IcedID, BokBot
Malware Config
C2 Extraction:
alishabrindeader.com
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments