MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 95ad74c1dff5293c49c955a4e77c17e6912c7b8d1fc8f5f4c6f05ac77a56a9ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 95ad74c1dff5293c49c955a4e77c17e6912c7b8d1fc8f5f4c6f05ac77a56a9ab
SHA3-384 hash: 8ede96fef778d289d63818f2194499ef7abf4a5add2aa673027f7f608aae886abd84ce42b0c85318b214236c0dbd1643
SHA1 hash: 0b21a4b04e79565e26e4236772d4605fc39862e7
MD5 hash: a146dac7b641fff2c5c3c0cf320731aa
humanhash: potato-bulldog-nitrogen-maryland
File name:PITCHPOT.DAT
Download: download sample
Signature IcedID
File size:1'086'464 bytes
First seen:2023-01-24 17:42:19 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 461b78f28d3ea5be2e2ffd3133d46dd3 (1 x IcedID)
ssdeep 24576:x7Vt9qfawrN27U1izzZaRbfp81L/Wm/nd6WrrUU9fQT:1BqfSU14Zadq1L/cWrrHfQ
TLSH T1A0356C46E6A505ECC067907543BAB153F7A1301A0364ADF74B929B292F2BF907D37B23
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter pr0xylife
Tags:1691396905 exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
267
Origin country :
BR BR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
PITCHPOT.DAT
Verdict:
Malicious activity
Analysis date:
2023-01-24 17:45:31 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Sigma detected: Execute DLL with spoofed extension
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 790898 Sample: PITCHPOT.DAT.exe Startdate: 24/01/2023 Architecture: WINDOWS Score: 48 39 Sigma detected: Execute DLL with spoofed extension 2->39 8 loaddll64.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        16 7 other processes 8->16 process5 18 rundll32.exe 10->18         started        20 WerFault.exe 9 12->20         started        22 conhost.exe 12->22         started        24 WerFault.exe 14->24         started        27 WerFault.exe 17 9 16->27         started        29 WerFault.exe 9 16->29         started        31 WerFault.exe 9 16->31         started        33 2 other processes 16->33 dnsIp6 35 WerFault.exe 4 9 18->35         started        37 192.168.2.1 unknown unknown 24->37 process7
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2023-01-24 18:10:22 UTC
File Type:
PE+ (Dll)
AV detection:
17 of 25 (68.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
95ad74c1dff5293c49c955a4e77c17e6912c7b8d1fc8f5f4c6f05ac77a56a9ab
MD5 hash:
a146dac7b641fff2c5c3c0cf320731aa
SHA1 hash:
0b21a4b04e79565e26e4236772d4605fc39862e7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments