🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4565f091b2a69c0c375ecdf3eb88c50d0ca38249ae135bc1f190015037124cde. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: 4565f091b2a69c0c375ecdf3eb88c50d0ca38249ae135bc1f190015037124cde
SHA3-384 hash: c75be089bf72b3d22f0268ea08e828a308292feea6a35e66f596328e554d483cfccd12a77fc3bac790178e75d4745e4b
SHA1 hash: 53f415023d644d52643bceafbb47aff57d77570c
MD5 hash: e0082ca22012aaf9d3b33803ea00f7b4
humanhash: sierra-yankee-fifteen-may
File name:redacted.document,11.14.22.zip
Download: download sample
Signature IcedID
File size:469'910 bytes
First seen:2022-11-15 00:35:01 UTC
Last seen:2022-11-16 23:36:14 UTC
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: office141122
ssdeep 12288:/A3xrZ0SMEjdUdGdOjCPuI91O9WH5QdIn9aJaa+WC:/8rdMEjdUd3CPuI91IS5Qan9aJaa+WC
TLSH T183A423D6936C9F656A81CB629EFF43D748CFCA21484085F35C268DFB83398DA846D4E1
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:1609463178 IcedID pw-office141122 zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
162
Origin country :
IE IE
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:run.cmd
File size:159 bytes
SHA256 hash: f96ca4d15febe51758689d9c93c5ff06449a67aacc9b619c249dd00f7b65d179
MD5 hash: bc2545a660518ef0271bdd6a8be3513c
MIME type:text/plain
Signature IcedID
File name:pss10r.chm
File size:402'249 bytes
SHA256 hash: be625229a8d2903ad4d680e47f8a93fc52cbd2e8b03594bb0e228797f786a7d4
MD5 hash: 8e5d477d42c9272448757883298cf37e
MIME type:application/octet-stream
Signature IcedID
File name:ver123.dll
File size:98'816 bytes
SHA256 hash: 77f25fef713c0e8c269c71f67d6c2aa162601ef4e41433777f6c4a131528eebb
MD5 hash: c002be28e6c72106ce93f8afed7ddba7
MIME type:application/x-dosexec
Signature IcedID
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:1609463178 banker loader trojan
Behaviour
Modifies Internet Explorer settings
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Malware Config
C2 Extraction:
trolspeaksunt.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments