MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 485ce80c6972762a04ff59597bdd71381688c73750e1dddae91ad33e8e6f01b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 485ce80c6972762a04ff59597bdd71381688c73750e1dddae91ad33e8e6f01b8
SHA3-384 hash: 1d629b4513d2c7f7595345c7fcc49d38d407098e4b1539af49aa3da10aef5586b429332b5d96d85b5f055bedb53520f2
SHA1 hash: b5616e8493bd77c73f95bad4e442360ab5abf4ed
MD5 hash: 08565af678a8f39bc7f6eda4f295c78d
humanhash: quiet-berlin-table-fish
File name:Fiapanfd.exe
Download: download sample
Signature IcedID
File size:2'408'448 bytes
First seen:2020-06-10 10:57:23 UTC
Last seen:2020-06-10 11:56:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c98c102a969a869775e75a3f478c16d3 (2 x IcedID)
ssdeep 49152:23+67gUbJWkxh+VsE/8Rmz2x+zlKlw+K5+f73g:4Z7gUtxh+J8Rmz2xyKlw/E7
Threatray 880 similar samples on MalwareBazaar
TLSH 95B58D227CA08577C17303355D4EF27837BEAE684B24864B26D03F1CBE7526316696AF
Reporter JAMESWT_WT
Tags:IcedID

Intelligence


File Origin
# of uploads :
2
# of downloads :
114
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Worm.Cridex
Status:
Malicious
First seen:
2020-06-09 08:04:35 UTC
File Type:
PE (Exe)
Extracted files:
18
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments