🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4737fd24701e6f3aff277fbac0fb7e7967bf755b76dbaa98642831e27d3d6770. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4737fd24701e6f3aff277fbac0fb7e7967bf755b76dbaa98642831e27d3d6770
SHA3-384 hash: 3a3aa2c697bdfe3a955d8a1565330f78c1d592685b5e3c6003fd4ecdf9226b4ef163c03a9b0ef1777843269a3bea9d36
SHA1 hash: fb986af636316f5c97971e1f1f9759e9b590b75b
MD5 hash: 7940e9b394abe28944e2035810cafd02
humanhash: montana-carolina-jersey-six
File name:182loader_p1_dll_64_n1_x64_inf.dll
Download: download sample
Signature IcedID
File size:309'760 bytes
First seen:2023-09-13 09:45:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c56f1dbe4ba57067106de2d65bb08668 (1 x IcedID)
ssdeep 6144:IOXtutuAZoWIn7Csid4BXGeg6QquQkCpj:B9u4AKWIn7eFounE
TLSH T1CB64296291B524ADE12340B88EEF9553E2B2701C03B07ECFF95896646F5FFA1717B284
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter Mangusta
Tags:909843654 exe IcedID key-arbalet875 vocesdelatinoamerica-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
407
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
182loader_p1_dll_64_n1_x64_inf.dll
Verdict:
No threats detected
Analysis date:
2023-09-13 09:39:55 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cobalt greyware masquerade packed
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Found PHP interpreter
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1308265 Sample: 182loader_p1_dll_64_n1_x64_... Startdate: 14/09/2023 Architecture: WINDOWS Score: 52 24 Multi AV Scanner detection for submitted file 2->24 26 Found PHP interpreter 2->26 7 loaddll64.exe 1 2->7         started        process3 process4 9 rundll32.exe 7->9         started        12 rundll32.exe 7->12         started        14 cmd.exe 1 7->14         started        16 8 other processes 7->16 signatures5 28 Found PHP interpreter 9->28 18 WerFault.exe 18 9->18         started        20 WerFault.exe 20 16 12->20         started        22 rundll32.exe 14->22         started        process6
Threat name:
Win64.Trojan.IcedID
Status:
Suspicious
First seen:
2023-09-13 09:46:05 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
4737fd24701e6f3aff277fbac0fb7e7967bf755b76dbaa98642831e27d3d6770
MD5 hash:
7940e9b394abe28944e2035810cafd02
SHA1 hash:
fb986af636316f5c97971e1f1f9759e9b590b75b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments