🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6517ef2c579002ec62ddeb01a3175917c75d79ceca355c415a4462922c715cb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 6517ef2c579002ec62ddeb01a3175917c75d79ceca355c415a4462922c715cb6
SHA3-384 hash: c457669b7a0fb2f0d6dc10080a61733b944a56cbe552fd6ecc445db7ded8bde5d5acc869540d6cbd081748ed408867ad
SHA1 hash: f82505f4699ed2df7a1a9fb46a12005f8528a175
MD5 hash: eaf85e9f10d0e3079484391d29307ae9
humanhash: neptune-pip-south-happy
File name:amd64.exe
Download: download sample
Signature IcedID
File size:382'976 bytes
First seen:2023-01-27 03:33:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash bbd59785b831ba0244fd5ab3586920bd (2 x IcedID)
ssdeep 6144:b0FOhm3Y1LfpDqnkIBwcu/oDdzr88vAHC/X7ysDPXoPcTPinEgrTytlRNKIg8ggd:b0km3YYY/ohhvAHC+WPXoPcTPbgrmtlC
Threatray 1'319 similar samples on MalwareBazaar
TLSH T1F7847353D77250E5D8BAC2398A677227B9F4382543349BD39710566A0F72FF0AA3E384
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter adm1n_usa32
Tags:exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
286
Origin country :
US US
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
Scan_Invoice_12-09#46.msi
Verdict:
Malicious activity
Analysis date:
2022-12-12 18:29:35 UTC
Tags:
trojan icedid

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
EvasionQueryPerformanceCounter
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
icedid packed
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 792731 Sample: amd64.exe Startdate: 27/01/2023 Architecture: WINDOWS Score: 56 31 Antivirus / Scanner detection for submitted sample 2->31 33 Multi AV Scanner detection for submitted file 2->33 8 loaddll64.exe 1 2->8         started        process3 process4 10 rundll32.exe 8->10         started        12 cmd.exe 1 8->12         started        14 rundll32.exe 8->14         started        16 7 other processes 8->16 process5 18 WerFault.exe 11 10->18         started        21 rundll32.exe 12->21         started        23 WerFault.exe 4 9 14->23         started        25 WerFault.exe 9 16->25         started        dnsIp6 29 192.168.2.1 unknown unknown 18->29 27 WerFault.exe 17 9 21->27         started        process7
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2022-12-12 18:28:09 UTC
File Type:
PE+ (Dll)
AV detection:
23 of 39 (58.97%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
6517ef2c579002ec62ddeb01a3175917c75d79ceca355c415a4462922c715cb6
MD5 hash:
eaf85e9f10d0e3079484391d29307ae9
SHA1 hash:
f82505f4699ed2df7a1a9fb46a12005f8528a175
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments