🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82a01607ebdcaa73b9ff201ccb76780ad8de4a99dd3df026dcb71b0f007456ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 82a01607ebdcaa73b9ff201ccb76780ad8de4a99dd3df026dcb71b0f007456ed
SHA3-384 hash: 1ed63bb61324e28e5dd0738005ad515db62010d5208a18a70fcbe9f117bbaef933c4034e6df488ef8839ffaa29ccf86a
SHA1 hash: 1be963d2108dc215b895f8e6fbb96c4bc50b1eff
MD5 hash: 5e28d3bdbb2970f2f5a57dd67b85c255
humanhash: texas-quebec-twenty-pizza
File name:w0.log
Download: download sample
Signature IcedID
File size:820'196 bytes
First seen:2023-10-16 15:55:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 70035c2f670535a761d9eee3735e0d53 (2 x IcedID)
ssdeep 6144:GhQd+ZW/3TvUCWysU2XN92nIMkS9yjygIL1ZaquKIwsjd5vRukMi/mf+0Hlqn//J:sEv9yjpIrH6BjfEkPmt+/bYujcpZ
TLSH T13C0519056BE924E4F1B78A79A9B79446FB76BC002F35CADF1151420E1E73FC0863A726
TrID 43.3% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
27.6% (.EXE) Win64 Executable (generic) (10523/12/4)
13.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.3% (.EXE) OS/2 Executable (generic) (2029/13)
5.2% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter proxylife
Tags:1180344712 exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
532
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Gathering data
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
cobalt crypto masquerade overlay packed
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2023-10-16 15:56:08 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
18 of 23 (78.26%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
82a01607ebdcaa73b9ff201ccb76780ad8de4a99dd3df026dcb71b0f007456ed
MD5 hash:
5e28d3bdbb2970f2f5a57dd67b85c255
SHA1 hash:
1be963d2108dc215b895f8e6fbb96c4bc50b1eff
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments