🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 949e992a9a4056cd8bf69feda32d855b533b9d7b83d11468c6bbf47a9f1bbc78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 949e992a9a4056cd8bf69feda32d855b533b9d7b83d11468c6bbf47a9f1bbc78
SHA3-384 hash: 89af665f3f937550da8a48c504aad38e0c39ec71de4352770c66bf0f23b7a874d3cbf051e1408416c2ee3ecf58276563
SHA1 hash: c137f77d57e520812c481f431fdd1cec9ced4686
MD5 hash: de34d2613853f4b55d56b89f59b38ed0
humanhash: wisconsin-hotel-nuts-princess
File name:Paid_Offer_54_Jan_19.iso
Download: download sample
Signature IcedID
File size:2'228'224 bytes
First seen:2023-01-20 00:32:41 UTC
Last seen:Never
File type: iso
MIME type:application/octet-stream
ssdeep 24576:akmZDEMHhp9v1Ikbn3ND0TAVOsIut8P4zlIKE2r/7Bk:PmZFHhp9v1Io3h0TA3pJk
TLSH T1D2A5AD65F66C0AA9C43BA17CC90B160AE9B23406477097DF03E64BB97E3B7D5263B311
TrID 99.6% (.NULL) null bytes (2048000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
0.0% (.SMT) Memo File Apollo Database Engine (88/84)
Reporter proxylife
Tags:3108046779 IcedID iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
IE IE
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:painstaking.dat
File size:1'026'440 bytes
SHA256 hash: 265c1857ac7c20432f36e3967511f1be0b84b1c52e4867889e367c0b5828a844
MD5 hash: d0515acd0a80ad5273ad189e72aca86f
MIME type:application/x-dosexec
Signature IcedID
File name:nayairguyb.cmd
File size:1'568 bytes
SHA256 hash: 8c82587698a93adedff06bf46ff5a4d16b318b75010519f6676ecfb49f4dd162
MD5 hash: c7baf62bda1704eda2a82f2c12573cdd
MIME type:text/plain
Signature IcedID
File name:Inv_Document.lnk
File size:1'978 bytes
SHA256 hash: 07ba4b9738b86155765196091d9eab41d5505564b0331d9257f4885a88de6724
MD5 hash: 5f473fd0d4282ce71f193d1902a8ce95
MIME type:application/octet-stream
Signature IcedID
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
icedid overlay packed
Threat name:
Shortcut.Trojan.IcedID
Status:
Malicious
First seen:
2023-01-20 00:33:09 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
5 of 39 (12.82%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments