🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 50f91b3d0c9c88a7282b4ebd726d4b4e11dcbc1059cb0e8da88cfca65e7fc6aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 50f91b3d0c9c88a7282b4ebd726d4b4e11dcbc1059cb0e8da88cfca65e7fc6aa
SHA3-384 hash: 7952680bfe6046b9eeeb3a7c806e275a147ebab36c2d46c7b7e4602ff9b5415fd0304e3eaaa447b1637810986e2a09ec
SHA1 hash: 7aeccd7bef27647b192b1e4b16512b4c75a4530e
MD5 hash: 869b7e394df6045c8dd9f1364b15c754
humanhash: december-vegan-kentucky-diet
File name:inv-CWYdpk-kFZDFnwKs.iso
Download: download sample
Signature IcedID
File size:1'429'504 bytes
First seen:2022-10-20 08:18:11 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 24576:4t3yANKRLSPSxQVjLzbC1YtjEmKAt15/FbTZDnClpbGQT8MJF:wXKpWdK1YnbT1CbbGk8MJF
TLSH T1B16533FC3297B1C1C25E177506F6240DC5B34901A20DACB87A7C75EA6BB2994EB2D32D
TrID 99.4% (.NULL) null bytes (2048000/1)
0.2% (.ISO) ISO 9660 CD image (5100/59/2)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter apps_ir
Tags:IcedID iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
n/a
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:jbmgHyNYx.6y0Z
File size:69'120 bytes
SHA256 hash: ea99b03e8484be6526a12f45608d6849ff612cdca324858bedeab6d88c1a38be
MD5 hash: 3cf2ff3d8771074fcedb21fc80b68833
MIME type:application/x-dosexec
Signature IcedID
File name:ztbxJB5p.cmd
File size:47 bytes
SHA256 hash: d1ccf4def00ba4979122235d2e04462cfb64952dd34ec7953bd145d9b546aec8
MD5 hash: c4f50cb90ef13fb064bc64ad8201e72a
MIME type:text/plain
Signature IcedID
File name:Ugi7se3aX.png
File size:983'189 bytes
SHA256 hash: 0b3e914d18dfbef677920f7daba83ab8633c19acfcd8c7f51f8c2962ad22756b
MD5 hash: 22e84540c8b2fec2743748978735168d
MIME type:image/png
Signature IcedID
File name:inv-CWYdpk-kFZDFnwKs.lnk
File size:1'794 bytes
SHA256 hash: 45997059b86bbdf344c7b870572bba61fa793a0304fdc5454dcda71dc1837560
MD5 hash: a3fd11bc1ccf1015b12bf418fe50234d
MIME type:application/octet-stream
Signature IcedID
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
masquerade
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2022-10-20 12:18:11 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
13 of 41 (31.71%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:1217988127 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
IcedID, BokBot
Malware Config
C2 Extraction:
seddkomaautomat.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:iso_lnk
Author:tdawg

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments