🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 76bcdbd0b4f4d9db2d11ec26a3becfcd3b17049efa4bceb0e32fa7e4c1d004a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 76bcdbd0b4f4d9db2d11ec26a3becfcd3b17049efa4bceb0e32fa7e4c1d004a1
SHA3-384 hash: 038e62e8827a639fe619ec816af9f83765d4ba6f35ad21886d2b0b16a465a6179804afd2c2c6e5ea1ef36592bd615f84
SHA1 hash: eaa65d3de8c15d905cbcefb15ffb3df159aadc40
MD5 hash: f08ffc855b9d9de8fca32c4da5f0f585
humanhash: march-utah-lima-eight
File name:f08ffc855b9d9de8fca32c4da5f0f585.dll
Download: download sample
Signature IcedID
File size:4'028'928 bytes
First seen:2022-12-20 09:55:32 UTC
Last seen:2022-12-20 11:32:25 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 2c974d07f3a49352022eb09a7a9494cd (1 x IcedID)
ssdeep 24576:uH8Pf2oZ6/u/ILJl0yo3iHc1LVlwJt4AfVGj3d+j5gn3jpp13WOTVPC4K9JKZq+C:wfP5gnzppkoCTDv+oAcSHY
TLSH T1171692479A7256F0D47AD23D8257262BF83138998330A3E7A7D55B062B917F0A73D3C8
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter abuse_ch
Tags:dll exe IcedID

Intelligence


File Origin
# of uploads :
2
# of downloads :
250
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
f08ffc855b9d9de8fca32c4da5f0f585.dll
Verdict:
Malicious activity
Analysis date:
2022-12-20 09:59:33 UTC
Tags:
cobalt

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Launching the default Windows debugger (dwwin.exe)
Gathering data
Result
Threat name:
CobaltStrike
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected CobaltStrike
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 770557 Sample: U64qqcsvln.exe Startdate: 20/12/2022 Architecture: WINDOWS Score: 68 20 boralob.com 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Yara detected CobaltStrike 2->26 28 C2 URLs / IPs found in malware configuration 2->28 8 loaddll64.exe 1 2->8         started        signatures3 process4 process5 10 cmd.exe 1 8->10         started        12 conhost.exe 8->12         started        14 regsvr32.exe 8->14         started        16 rundll32.exe 8->16         started        process6 18 rundll32.exe 10->18         started       
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2022-12-20 00:13:47 UTC
File Type:
PE+ (Dll)
AV detection:
11 of 39 (28.21%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
cobaltstrike
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Verdict:
Informative
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
76bcdbd0b4f4d9db2d11ec26a3becfcd3b17049efa4bceb0e32fa7e4c1d004a1
MD5 hash:
f08ffc855b9d9de8fca32c4da5f0f585
SHA1 hash:
eaa65d3de8c15d905cbcefb15ffb3df159aadc40
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

Executable exe 76bcdbd0b4f4d9db2d11ec26a3becfcd3b17049efa4bceb0e32fa7e4c1d004a1

(this sample)

  
Delivery method
Distributed via web download

Comments