🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e7d5c84776e2b69eefc5958ec2dab814218fd5dd2e9f6a107833e2553bba5e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7e7d5c84776e2b69eefc5958ec2dab814218fd5dd2e9f6a107833e2553bba5e9
SHA3-384 hash: 64f3f857b899c75e01829b80e840bc339fbe19d9816997a90a6637bfa76b56be827a5fcf35193dccb386e7470bea6aa3
SHA1 hash: d5c932ae969dab0b88284d35682e87ca78aaf215
MD5 hash: 868912cc99260831d53307adaaba6e2a
humanhash: magnesium-wisconsin-music-eight
File name:Document_09_13_927.zip
Download: download sample
Signature IcedID
File size:11'487 bytes
First seen:2023-09-14 08:52:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:YDATs1ByVsJz8vVvqE0iYxd7114WY5fxYUvzCIji39yzmYtPzExUO5vQdkWMCyb3:dio2AvklL7kWY5f+gs3KmUHg4d/MN/7P
TLSH T18032B0CC400B5571F6C7843D742B95E90388FB5FA5B26151B809EED470A03EAE68491F
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter Mangusta
Tags:1638996626 IcedID laurellkhamilton-shubhmishra-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
180
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Document_09_13_927.js
File size:44'662 bytes
SHA256 hash: 32ee3a4074bff70f212b88233f37f72796982c3e579fcdcc7c773ae5c41ae010
MD5 hash: 03677c4079fafd6413c5552f3d6da926
MIME type:text/plain
Signature IcedID
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive lolbin lolbin obfuscated replace rundll32
Threat name:
Script-JS.Trojan.IcedID
Status:
Malicious
First seen:
2023-09-14 08:53:05 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:1638996626 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Downloads MZ/PE file
IcedID, BokBot
Malware Config
C2 Extraction:
minutozhart.online
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments