🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3c3024e4c2b075b12063e4af1bb3886d4e7ee25e8d1bb4fc52ea51535ab1e1ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 3c3024e4c2b075b12063e4af1bb3886d4e7ee25e8d1bb4fc52ea51535ab1e1ae
SHA3-384 hash: fa6360e75f89b5b08f5ccdf64bbc57925ec0defdf0de3029102be13e9f98a721b9c4be9dbf2e158e9db8a19c94312198
SHA1 hash: 8ff38fa6f072d07f9d767f991d9cc57c59030ada
MD5 hash: 0eba555b92d3fe517381d13207015089
humanhash: lion-finch-gee-california
File name:3c3024e4c2b075b12063e4af1bb3886d4e7ee25e8d1bb4fc52ea51535ab1e1ae
Download: download sample
Signature IcedID
File size:66'914 bytes
First seen:2021-09-29 08:10:21 UTC
Last seen:Never
File type:unknown
MIME type:application/octet-stream
imphash e0a50dc3fd59f4d700df0d8bd00d3fe2 (1 x IcedID)
ssdeep 1536:SDNz2EdUapfw5SS0ZNjEVwzo/TgPMSMWr9C2:SDNDdUa111ZZEkoLgPtMr2
Threatray 5'736 similar samples on MalwareBazaar
TLSH T183634C5FB3451772D78203B2370FADC6BB2A9475327A88D0546D805E232AE68D3FB395
Reporter JAMESWT_WT
Tags:IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
400
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2021-09-27 18:54:00 UTC
AV detection:
36 of 45 (80.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_icedid_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.icedid.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments