MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 56edc2e0d3d9cb181fc4d861cdbca6a960f576ce10d93f1a7ad18d80624185d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
IcedID
Vendor detections: 7
| SHA256 hash: | 56edc2e0d3d9cb181fc4d861cdbca6a960f576ce10d93f1a7ad18d80624185d5 |
|---|---|
| SHA3-384 hash: | 8f8ebd0897ed0c9d67e559176e4cc002b951676e387af64e5369ef81b22d774460188a0d631d62ab73e49d94d93835d2 |
| SHA1 hash: | dac5d441cb4a77ca61e61b2c0b440d091ff74c7b |
| MD5 hash: | dc088c3c043898570b808e2d8bb271b4 |
| humanhash: | equal-burger-september-stream |
| File name: | LyuSP.txt |
| Download: | download sample |
| Signature | IcedID |
| File size: | 348'162 bytes |
| First seen: | 2020-10-19 16:49:35 UTC |
| Last seen: | 2020-10-19 17:51:44 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 4a8af3905b9fdbb1ef58c7e749a5b73f (3 x IcedID) |
| ssdeep | 6144:wITsK33t255j1REB87RuBb2W4TkUPuL8xCsfR8A5etAONju9S9:NN3y11qCYmkzL8xCsdetTF9 |
| Threatray | 129 similar samples on MalwareBazaar |
| TLSH | 9974AE11B6C184B6C67E56383834CF611ABDBC1119B89D6B63D03D6F6E38AC29731E63 |
| Reporter | |
| Tags: | dll IcedID Shathak TA551 |
Intelligence
File Origin
# of uploads :
2
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Detection:
IcedID
Detection(s):
Result
Verdict:
Malware
Maliciousness:
Behaviour
Sending a UDP request
DNS request
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2020-10-19 16:51:04 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
5/5
Verdict:
malicious
Label(s):
icedid
gozi
Similar samples:
+ 119 additional samples on MalwareBazaar
Result
Malware family:
icedid
Score:
10/10
Tags:
trojan banker family:icedid
Behaviour
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Blacklisted process makes network request
IcedID, BokBot
Unpacked files
SH256 hash:
172be548df5ffb544367dfd07e069cdbd8be78facf6be331c6d0598b0aac4eb0
MD5 hash:
885507a39eb9da642c2673d00e57c8a7
SHA1 hash:
c154c01278f8a3e1739d0743ebe0784dcb9187c4
SH256 hash:
56edc2e0d3d9cb181fc4d861cdbca6a960f576ce10d93f1a7ad18d80624185d5
MD5 hash:
dc088c3c043898570b808e2d8bb271b4
SHA1 hash:
dac5d441cb4a77ca61e61b2c0b440d091ff74c7b
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.