🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5adf5de2bd216c2d88341118dc0498eb86f8a10842a476f103ba2b7b4f8f36e4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: 5adf5de2bd216c2d88341118dc0498eb86f8a10842a476f103ba2b7b4f8f36e4
SHA3-384 hash: 4ab06b2dd5187adf39a5a61bf0c5e615019eafea4659dd644cc003d8de37d1b04526adde95246afbffe8944f24725676
SHA1 hash: 6c41e7f8b8ba16db8769aed795a07ec546ef9a56
MD5 hash: 3b9447569f4f5403d62f607061cff0e7
humanhash: uniform-california-queen-xray
File name:Mar_02_Contract_19.iso
Download: download sample
Signature IcedID
File size:1'572'864 bytes
First seen:2023-03-02 19:51:57 UTC
Last seen:Never
File type: iso
MIME type:application/octet-stream
ssdeep 6144:pn3FMevnrsIgeWvFTNKgxOkcIcVfSIzl0Hw3USlXeWcCT7n7rb1NbmpLC7Aar53:pn3FMEo75KPkcIcpN50C1NbmpGFr5
TLSH T1C0753A1667E80459F4FB5B789ABB860DE776F861273196CF02A0813D1F33BC55A38B21
TrID 99.6% (.NULL) null bytes (2048000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
0.0% (.SMT) Memo File Apollo Database Engine (88/84)
Reporter proxylife
Tags:IcedID iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
JP JP
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:preprograming.dat
File size:360'488 bytes
SHA256 hash: 2fd37077734a03d479fa0781166142e9283689b066acbecddaf35f1b24f0280b
MD5 hash: ac5cf9e98eb327b7b347a2a26f1850ca
MIME type:application/x-dosexec
Signature IcedID
File name:03_02_Scan.cmd
File size:1'525 bytes
SHA256 hash: 4e6ba7d0861ff71f770c6f0adfd5c06b8a726bea25ec1c651144b4d294f90a90
MD5 hash: d7320d594d0834fa37c3e1aa632770c3
MIME type:text/plain
Signature IcedID
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
83%
Tags:
hacktool overlay packed
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:IcedIDPackerD
Author:kevoreilly
Description:IcedID export selection

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments