🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 310b9b7f54880f2142882e39637d73dfc8542eab06ac1bb9ec597b801979b4d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 310b9b7f54880f2142882e39637d73dfc8542eab06ac1bb9ec597b801979b4d8
SHA3-384 hash: 6f0408b23a9ae9db24269fb4b13b0cf28178abcc77945f606993ab3c1096cc8e4759c3cdc341a4821fba7a442ce8d32f
SHA1 hash: 34753041288f8065b0ef06a85d29f04dd7d83193
MD5 hash: 20302a74244dcc2ceab26d846ff6fb8f
humanhash: connecticut-kansas-bakerloo-fanta
File name:Sr.xll
Download: download sample
Signature IcedID
File size:12'288 bytes
First seen:2023-09-26 10:57:21 UTC
Last seen:2023-09-26 12:05:49 UTC
File type:Excel file xll
MIME type:application/x-dosexec
imphash 7a749f356ac5154c19dc852acb78447f (2 x IcedID)
ssdeep 192:MGuG9QfaDPYcrSf6MJOSxGp/AhEPEjr7AhDX:HuG9tQcrS5JOFBA1r7CD
TLSH T1C442C60DB77244BCC916D270C5FB87B1F6B2F4111263862F07E0C7775EB0A69662AE49
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter proxylife
Tags:135-125-177-95 2678990133 IcedID xll

Intelligence


File Origin
# of uploads :
2
# of downloads :
182
Origin country :
AO AO
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Behaviour
BlacklistAPI detected
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
anti-debug cmd lolbin shell32
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Obfuscated command line found
Sigma detected: Execute DLL with spoofed extension
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1314443 Sample: Sr.xll Startdate: 26/09/2023 Architecture: WINDOWS Score: 52 50 Sigma detected: Execute DLL with spoofed extension 2->50 8 loaddll64.exe 1 2->8         started        process3 process4 10 rundll32.exe 1 8->10         started        13 rundll32.exe 1 8->13         started        15 rundll32.exe 8->15         started        17 3 other processes 8->17 signatures5 52 Obfuscated command line found 10->52 19 cmd.exe 1 10->19         started        21 cmd.exe 13->21         started        23 WerFault.exe 11 15->23         started        25 rundll32.exe 17->25         started        27 WerFault.exe 9 17->27         started        process6 process7 29 curl.exe 2 19->29         started        32 conhost.exe 19->32         started        34 rundll32.exe 19->34         started        36 timeout.exe 1 19->36         started        38 conhost.exe 21->38         started        40 curl.exe 1 21->40         started        42 timeout.exe 1 21->42         started        44 rundll32.exe 21->44         started        46 WerFault.exe 20 9 25->46         started        dnsIp8 48 135.125.177.95, 49781, 49782, 80 AVAYAUS United States 29->48
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2023-09-26 10:58:05 UTC
File Type:
PE+ (Dll)
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Loads dropped DLL
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Find_Any_Xll_Files
Author:David Ledbetter @Ledtech3
Description:Find Any XLL File

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments