MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3700f2c5fe27c80e41984b2a55f236655a09f0781c05b265bccb26165318d78a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 3700f2c5fe27c80e41984b2a55f236655a09f0781c05b265bccb26165318d78a
SHA3-384 hash: 7afb83f1327b5bc34711561f079e3882d4d33a66beaa8f2dc3767139baff37163aed751de30c5b420201e8ac75754715
SHA1 hash: e3bbd92b95ac4085b5882afec2140737afecad71
MD5 hash: ad158a69eab5d63ed62f8c097c593604
humanhash: carbon-four-beryllium-fruit
File name:SecuriteInfo.com.FileRepMalware.2557
Download: download sample
Signature IcedID
File size:89'600 bytes
First seen:2020-03-21 00:57:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 71705763605f287903366fc14660ff3e (1 x IcedID)
ssdeep 768:hcI+QGF7WTUwhmBaaKo060kOmQOFRJg2E9Tdr4rOP/JB958IXtnV1k287eF58nCk:tCWTUwMEaKx64mJo34OP/P9SESugbjt
Threatray 665 similar samples on MalwareBazaar
TLSH 39931643B785D162E5860AB4C8A7EBFD4A37BC544B1146CB67907F1F3D322E1AE32186
Reporter @SecuriteInfoCom
Tags:IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
FR FR
Mail intelligence
No data
Vendor Threat Intelligence

YARA Signatures


MalareBazaar uses YARA rules from several public and non-public repositories, such as Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious proccess dumps they may create. Please note that only results from TLP:WHITE rules are being displayeyd.

Rule name:Cobalt_functions
Author:@j0sm1
Description:Detect functions coded with ROR edi,D; Detect CobaltStrike used by differents groups APT

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

Executable exe 3700f2c5fe27c80e41984b2a55f236655a09f0781c05b265bccb26165318d78a

(this sample)

  
Delivery method
Distributed via web download

Comments