🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 527fbfad3a7393d22732e5a3f845939fd576cd09e958b97b84368dcf6020bf29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA 3 File information Comments

SHA256 hash: 527fbfad3a7393d22732e5a3f845939fd576cd09e958b97b84368dcf6020bf29
SHA3-384 hash: 195a98d13f44476716ab6c84dd886c28ef6ff9f3bda0d8664a1757fb98b0c63d05adf73e98ee4eb1cb71a2422fd9ee43
SHA1 hash: 2cd21f26b127967ec52183da28239117b634b83c
MD5 hash: 4fdacba51fb28120fc87c8381b602842
humanhash: earth-twelve-berlin-chicken
File name:LS71.vhd
Download: download sample
Signature IcedID
File size:2'109'440 bytes
First seen:2022-12-07 18:07:14 UTC
Last seen:2022-12-12 15:57:35 UTC
File type:
MIME type:application/x-virtualbox-vhd
ssdeep 12288:Pq2cYoxqZUOaGwabOpO/HHpw15O//3777777LwmqL9F3u:CxGvwcHHpw15OXkZF3u
TLSH T139A56C13E38003B9C5774374A78E52E1F721FC3933209965645EB6BD3A32DA9463E6E8
Reporter proxylife
Tags:3738574432 IcedID vhd

Intelligence


File Origin
# of uploads :
2
# of downloads :
199
Origin country :
RU RU
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd cmd.exe vhd
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:hunt_susp_vhd
Author:SBousseaden
Description:Virtual hard disk file with embedded PE
Rule name:SUSP_VHD_Suspicious_Small_Size
Author:Florian Roth
Description:Detects suspicious VHD files
Reference:https://twitter.com/MeltX0R/status/1208095892877774850
Rule name:SUSP_VHD_Suspicious_Small_Size_RID3285
Author:Florian Roth
Description:Detects suspicious VHD files
Reference:https://twitter.com/MeltX0R/status/1208095892877774850

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments