🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 61e30e5027e36f945125634a1c363d2245404ec2d94071007fca55976dd6c2b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 61e30e5027e36f945125634a1c363d2245404ec2d94071007fca55976dd6c2b6
SHA3-384 hash: e02e481de7b7078e527acd73099017e5f43a01d47d7fcea8e70ef6c8771d32b366f01fb627f78e0b77f37e76bf797c1d
SHA1 hash: 833255426919a15c7d3a3c072a9829ad9b9bb261
MD5 hash: 08f1066319f0b180c9beec112d668250
humanhash: twenty-item-idaho-red
File name:c0l.vbs
Download: download sample
Signature IcedID
File size:49'337 bytes
First seen:2023-04-28 22:55:25 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 192:SFCM336eNh461dj9Zr4GoMICwfY9o7VPZqu+l1uSQeMOk5Za6zR0qcSd79zSaeug:iOj9K6saW8a8Svxc+
Threatray 17 similar samples on MalwareBazaar
TLSH T12323800399C1DB8D32F4F6A972F3E3A540E286374674BC14E23001BB8917FAB759B599
Reporter proxylife
Tags:3887211302 IcedID vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
174
Origin country :
RU RU
Vendor Threat Intelligence
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Windows Shell Script Host drops VBS files
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-04-28 18:07:32 UTC
File Type:
Text (VBS)
AV detection:
5 of 36 (13.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:3887211302 banker collection spyware stealer trojan
Behaviour
Discovers systems in the same network
Gathers network information
Gathers system information
Modifies registry class
Modifies system certificate store
Runs net.exe
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
outlook_win_path
Enumerates physical storage devices
Accesses Microsoft Outlook profiles
Checks computer location settings
Loads dropped DLL
Reads user/profile data of web browsers
Blocklisted process makes network request
Downloads MZ/PE file
IcedID, BokBot
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments