🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40ee60d2062d400cccec48d21b43cab507529fadee6014e9c90bc490b0c360ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: 40ee60d2062d400cccec48d21b43cab507529fadee6014e9c90bc490b0c360ca
SHA3-384 hash: 297dc372127999460508846e33342f4b8fe4d9e4a1a51d14ad198f51e01063ac8b424cf1133fee7a989c9614e183928b
SHA1 hash: 0c809943e48164e50ecf696fe388d212f27eeff5
MD5 hash: fc6f571a54ee964dcc5752c2dc72da10
humanhash: lithium-nitrogen-berlin-freddie
File name:ice-zip.zip
Download: download sample
Signature IcedID
File size:341'911 bytes
First seen:2023-02-16 19:58:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 6144:bDSKNIPllF6RXeA4HMm7PCA3N45UQxPnD+K2GR6DVzKbNzp:HSXh6RXfcbq5Fh73D
TLSH T1FF74237A97E7FAD697005B285F52402BC014595284070BAFB7C6B1BAB722BC7BD07D0B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:dll IcedID zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
257
Origin country :
RU RU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:c8e0e743397406f6c7c15588ef767fda
File size:855'040 bytes
SHA256 hash: 168e8a92e64f024346dd703ed9356f4e0bdf7d2130048e68da36291bbc9421a1
MD5 hash: c8e0e743397406f6c7c15588ef767fda
MIME type:application/x-dosexec
Signature IcedID
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug icedid
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:IcedIDPackerD
Author:kevoreilly
Description:IcedID export selection

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments