🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3402a2fc0b043e196115fa4bef0e85306955bd3a8e465bfb737a48df2b17d6f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3402a2fc0b043e196115fa4bef0e85306955bd3a8e465bfb737a48df2b17d6f6
SHA3-384 hash: c74cd795e0caf699abb45dd8366cc50d7b53d5dc1b1bf7b5a17cfd137bc9e3e5a8b72816e857940a3ee2e65b2a1df1ed
SHA1 hash: f50f446a0af79cfcfa421dcd4492d225755bab35
MD5 hash: 18ea38f072df0b6a4d394c451a26a65f
humanhash: equal-monkey-stairway-mango
File name:Docs822.zip
Download: download sample
Signature IcedID
File size:399'739 bytes
First seen:2022-12-14 18:48:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: Zoom1222
ssdeep 12288:TWf80paH3YedO2neg7xPRRSzsxVIHN++pvkhWa5pX1:TWfmYedOIewRRSAItxkv1
TLSH T11A8423DFBF60C701FBBB92A199F1CE94179A334E0F7A9A4AD90C45608E4F7152E21118
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter k3dg3___
Tags:2302411646 IcedID klepdrafooip.com pw Zoom1222 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
US US
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:desktop.ini
File size:993'294 bytes
SHA256 hash: 591701e6e3ea61f8dfca07849668170ba5086b12022abd157dfb6d81f849e916
MD5 hash: 1bb0ca2e6ac4253b69917831f6e45c59
MIME type:application/x-dosexec
Signature IcedID
File name:DatabaseNDA-14310.lNK
File size:2'670 bytes
SHA256 hash: 7a3367528cbebf26612a7b3c6db5e73ecc437b0f41564581eb6d35f739c10bc4
MD5 hash: 91d36dfa00a703fa9ad73d1f6ef162f2
MIME type:application/octet-stream
Signature IcedID
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:2302411646 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
IcedID, BokBot
Malware Config
C2 Extraction:
klepdrafooip.com
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

zip 3402a2fc0b043e196115fa4bef0e85306955bd3a8e465bfb737a48df2b17d6f6

(this sample)

591701e6e3ea61f8dfca07849668170ba5086b12022abd157dfb6d81f849e916

  
Dropping
SHA256 591701e6e3ea61f8dfca07849668170ba5086b12022abd157dfb6d81f849e916
  
Delivery method
Distributed via e-mail attachment

Comments