🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fcc001e65fd53bd7ee288c5972ac58f4d8d12397ac6a2dd9c1aa85aa0e61235. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA 3 File information Comments

SHA256 hash: 8fcc001e65fd53bd7ee288c5972ac58f4d8d12397ac6a2dd9c1aa85aa0e61235
SHA3-384 hash: ebdb800c21a7bd913e94d8e03597b249c3543c83e4ab79fb3816bffeb1cc9dc3317fde7d98ca9564555cf1b923a6c5ef
SHA1 hash: 2674780c3aac37dc1a380941d6611b224aeb3edf
MD5 hash: e4c27c946ec3abf3d7ea2fd64019ccfe
humanhash: comet-chicken-cola-beryllium
File name:Document-755.iso
Download: download sample
Signature IcedID
File size:1'441'792 bytes
First seen:2023-01-17 17:50:13 UTC
Last seen:Never
File type: iso
MIME type:application/octet-stream
ssdeep 6144:16sbYTf1IFpSQjAsK67TbDkJGvPiaTB00Czya:4Nf67h0JGSaTi
TLSH T1D7658D42A6A00CB2DCBB8375859B4A0EE7F1B49513A5D34B47F486762F377A03A2C3D5
TrID 99.6% (.NULL) null bytes (2048000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
0.0% (.SMT) Memo File Apollo Database Engine (88/84)
Reporter malwarelabnet
Tags:IcedID iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
n/a
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:unfaltering.dat
File size:233'864 bytes
SHA256 hash: c06805b6efd482c1a671ec60c1469e47772c8937ec0496f74e987276fa9020a5
MD5 hash: 8d1643234a00b1c0b89e326fcd66ba6c
MIME type:application/x-dosexec
Signature IcedID
File name:rampewcadL.cmd
File size:1'489 bytes
SHA256 hash: d54f40fc854f159a4b4d7842d7ac11c7c812c3399ef6024761bdae2fcd8f0a9f
MD5 hash: f78b3a422641abe6b8559db3c098a731
MIME type:text/plain
Signature IcedID
File name:Scan.lnk
File size:1'978 bytes
SHA256 hash: d796124c59a3789b56ea3ab3ffba87d918f951fad8080c806e1d7c4750246ea9
MD5 hash: 198f3ceb55f359d675fd4d4c69ed72e3
MIME type:application/octet-stream
Signature IcedID
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2/10
Confidence:
80%
Tags:
overlay packed
Threat name:
Script-BAT.Trojan.IcedIDLNK
Status:
Malicious
First seen:
2023-01-17 17:51:07 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
5 of 39 (12.82%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments