🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 778f1cbd036de33d6e6eb5b0face18c276732e365111bdfae447b30ccfebf8c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 2


Intelligence 2 IOCs YARA 2 File information Comments

SHA256 hash: 778f1cbd036de33d6e6eb5b0face18c276732e365111bdfae447b30ccfebf8c5
SHA3-384 hash: a00caf34c1ad292ca0e1d903f59f05dc2936762a6d5d78fc8da9ee3245fed2bc298c658f2e95e8b0d23387dd3eeed904
SHA1 hash: ebf2a4a2d0340d1fd6408dc8b47e8dfcc2e4cc81
MD5 hash: 2142f4dca9dc32d3d3ddb120c97ab879
humanhash: utah-venus-bravo-angel
File name:Document-2325.zip
Download: download sample
Signature IcedID
File size:145'276 bytes
First seen:2023-01-16 17:45:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 53842
ssdeep 3072:mxqewEycnqLziWCMzfBC2qD+FXfVeeqz9xEPDSVYzv9:DenykqitMzfBXqu7RP2VYzv9
TLSH T1D0E3220DDF0AECD1ED01EBEE588BE9AC33A5D69D44229E7F6C44E315038F39485621E5
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:3074491541 IcedID pw-53842 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
137
Origin country :
IE IE
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:vatphiefts.cmd
File size:1'503 bytes
SHA256 hash: 95c7ec322d35e25ed95ff77a0f7e05352158b6a5b921ebd93a06e37072d8e6ee
MD5 hash: 4eee6504e19fd9b445a4a0b33bb8605c
MIME type:text/plain
Signature IcedID
File name:kickboxing.dat
File size:233'864 bytes
SHA256 hash: c06805b6efd482c1a671ec60c1469e47772c8937ec0496f74e987276fa9020a5
MD5 hash: 8d1643234a00b1c0b89e326fcd66ba6c
MIME type:application/x-dosexec
Signature IcedID
File name:REF_Scan_01-16.lnk
File size:1'978 bytes
SHA256 hash: 377aaa472ab194cdd112cc225fcf56e37506685186df6e9508347bf9ae78d5fc
MD5 hash: c19a1aba477f5badff7564fb919e19ee
MIME type:application/octet-stream
Signature IcedID
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments