MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7fe7bb068cc39ae8bdb2b379324f4e58814b5aa5f0bb15c38ccc504abf05a7ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7fe7bb068cc39ae8bdb2b379324f4e58814b5aa5f0bb15c38ccc504abf05a7ec
SHA3-384 hash: e69dad61c626e056615d5bdeb08131247e8cfa5fb0e7683180d2ebc7aef04f0c8a7420d7968497fed526570661837dc0
SHA1 hash: 4deedc3512e4d3d50027c1e5a5717f57c96a77b9
MD5 hash: 4e614ba0ad35cdcc15859a0ce633ef0c
humanhash: blue-pennsylvania-oscar-papa
File name:7fe7bb068cc39ae8bdb2b379324f4e58814b5aa5f0bb15c38ccc504abf05a7ec
Download: download sample
File size:163'898 bytes
First seen:2020-08-09 18:06:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a70dc1edb3b986c960e38d94e07f03cd
ssdeep 3072:Zo0jlsrx92vKzazm1mZmd8z0ZTduRlicNLWdGsl0W2D:Rjls6vfJoWz6Tc1c7U
Threatray 110 similar samples on MalwareBazaar
TLSH 82F3F0D8FC64D836E90BF1756891CC9F04403F4E062E82AB79D28E2BD72F648C6591BD
Reporter tildedennis
Tags:iceix


Avatar
tildedennis
iceix version 1.2.5.3

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching the default Windows debugger (dwwin.exe)
Sending a UDP request
Creating a window
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
a
c
d
e
f
g
h
i
L
M
n
o
p
r
s
t
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 260256 Sample: lIBUG4mF8V Startdate: 09/08/2020 Architecture: WINDOWS Score: 23 13 Machine Learning detection for sample 2->13 6 lIBUG4mF8V.exe 2->6         started        process3 process4 8 WerFault.exe 23 9 6->8         started        file5 11 C:\ProgramData\Microsoft\...\Report.wer, Little-endian 8->11 dropped
Threat name:
Win32.Trojan.Zeus
Status:
Malicious
First seen:
2012-02-20 00:18:00 UTC
File Type:
PE (Exe)
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments