🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ed2e75343ea0e5c8c6fc4de3b20f86b65e59a2c0cc91a35796052b2e1e7b389. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 3ed2e75343ea0e5c8c6fc4de3b20f86b65e59a2c0cc91a35796052b2e1e7b389
SHA3-384 hash: ae4a0446dcbac61627a0b6e86dd564e770ee9cfa801803d734a12c640c15acebaf4a4c6cc8adf68ef73db3c1c095bdcd
SHA1 hash: 673eedf5f187377500031b068e44d990475ea447
MD5 hash: dd04837eabe356e5ff7264fff875e5b3
humanhash: oklahoma-kilo-tennis-sierra
File name:1210.png
Download: download sample
Signature IcedID
File size:712'736 bytes
First seen:2023-06-23 17:30:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d43c0febfe7d9daede851a726111adf4 (1 x IcedID)
ssdeep 12288:GiZ2R7X+9iOJI76AUi77oizFCEeSUUE9NYJe44lYWvSwkU2lvzGtp9:46JI76Pf9Nn4MvSRU2lvzSn
TLSH T193E43A55ABB514A9E9F2C17C8A534A37E3B6F41413309FCF0661893A0F17BD82B3A758
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter malwarelabnet
Tags:exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
370
Origin country :
CA CA
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
1210.png
Verdict:
No threats detected
Analysis date:
2023-06-23 17:33:27 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade overlay packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
Changes memory attributes in foreign processes to executable or writable
Malicious sample detected (through community Yara rule)
Queues an APC in another process (thread injection)
System process connects to network (likely due to code injection or exploit)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected IcedID
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2023-06-23 17:31:07 UTC
File Type:
PE+ (Dll)
AV detection:
2 of 37 (5.41%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
3ed2e75343ea0e5c8c6fc4de3b20f86b65e59a2c0cc91a35796052b2e1e7b389
MD5 hash:
dd04837eabe356e5ff7264fff875e5b3
SHA1 hash:
673eedf5f187377500031b068e44d990475ea447
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments