🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3abf775b4cf70b7e0b86288320b3ce39483ea7b4b2073dc14204c2e229c9f6bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3abf775b4cf70b7e0b86288320b3ce39483ea7b4b2073dc14204c2e229c9f6bf
SHA3-384 hash: c485bf68a5c5200170665ebf77af6e36cd9cdbcde3ae84b366abf4eafd196b674b272c70c02dc2fb7e921d9e660aa95f
SHA1 hash: c724f6b737562e1bf9dcd149e5ec13f9631ae5c9
MD5 hash: 599872eb6e1076375f77f5a04ab167fb
humanhash: island-fanta-connecticut-south
File name:Setup_Win_13-02-2023_16-33-16.zip
Download: download sample
Signature IcedID
File size:820'729 bytes
First seen:2023-02-14 07:07:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:z6HjCojFMRGhROi0Pa0nGb/3T6OR2JnqikaSsqPTatEclmJvwD7RYcFeIik:z6HjvFMRTi1qO/3TaJnrSnCOoGEeI9
TLSH T12F0502A751FD6668F07589754EAE2CB9E76C860C861C1907EEB10407FB830EB2B9B164
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:2076641214 IcedID malvertising ms-teams zip


Avatar
abuse_ch
IcedID botnet C2:
http://alishabrindeader.com/

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup_Win_13-02-2023_16-33-14.exe
File size:742'701'568 bytes
SHA256 hash: 68fcd0ef08f5710071023f45dfcbbd2f03fe02295156b4cbe711e26b38e21c00
MD5 hash: 7327fb493431fa390203c6003bd0512f
MIME type:application/x-dosexec
Signature IcedID
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2023-02-14 02:47:46 UTC
AV detection:
7 of 26 (26.92%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:2076641214 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
IcedID, BokBot
Malware Config
C2 Extraction:
alishabrindeader.com
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

zip 3abf775b4cf70b7e0b86288320b3ce39483ea7b4b2073dc14204c2e229c9f6bf

(this sample)

  
Delivery method
Distributed via web download

Comments