🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79b34b9a6a93b06d52b12d2be08850eb3c8cfcc5c22fbd9e5facd42b1bfcddd0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 79b34b9a6a93b06d52b12d2be08850eb3c8cfcc5c22fbd9e5facd42b1bfcddd0
SHA3-384 hash: d1377e33239a47752fac46e3e4923561c062be9bd463a08b169f08e912ff5937688669f0a8c721be942d65114e23ef2b
SHA1 hash: 6c2392b6358be7387a6d8512ce46e9ac8c377c21
MD5 hash: 063246ba8a73e89237250a818211e1ae
humanhash: enemy-early-five-undress
File name:Setup_Win_10-02-2023_18-19-51.zip
Download: download sample
Signature IcedID
File size:952'900 bytes
First seen:2023-02-11 07:53:20 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:FKriEydUu7SralLFAdhDirZz3KmAcvbMljw5XvGM6p:61EUuWrGBAd0sZczMl05xW
TLSH T132151226B5819EEBECB80672AEF75D510349BC2C17B767DC41B8A5A731F6D74803081E
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:1494101503 file-pumped IcedID malvertising thunderbird zip


Avatar
abuse_ch
IcedID botnet C2:
staringgeipod.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup_Win_10-02-2023_18-19-50.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:742'879'384 bytes
SHA256 hash: dbc3e3c4ad4a0ee6623935dbc20dbe9d765f783c10b9e1f9e5774c935b06fe74
MD5 hash: 261631519ce1a1bb69b1a04a7700edcb
De-pumped file size:742'868'480 bytes (Vs. original size of 742'879'384 bytes)
De-pumped SHA256 hash: 5b6b7faa0ea35eaf6125c0886e79aca902b712c725cccc670bb06f9b8d9d3508
De-pumped MD5 hash: 692151d5bec9917bdf5ae0b47d05d174
MIME type:application/x-dosexec
Signature IcedID
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2023-02-11 08:15:14 UTC
AV detection:
6 of 26 (23.08%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:1494101503 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
IcedID, BokBot
Malware Config
C2 Extraction:
staringgeipod.com
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

zip 79b34b9a6a93b06d52b12d2be08850eb3c8cfcc5c22fbd9e5facd42b1bfcddd0

(this sample)

  
Delivery method
Distributed via web download

Comments