MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab037590458a18587639666fe8a6b68e64b2bcae099df9c3b631e3ed4be1ce20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ab037590458a18587639666fe8a6b68e64b2bcae099df9c3b631e3ed4be1ce20
SHA3-384 hash: 816b986a6c99802251bc4a004be82a359fcd4f6d9696d54ef1077b93dce94b605cd1ee52398c1e9853468c0622377141
SHA1 hash: 76a91430be5dd3f5904e70881a13939e3fcc8769
MD5 hash: eb3bef5498794d476a91588715d0397f
humanhash: seven-december-jig-sodium
File name:temp.tmp
Download: download sample
Signature IcedID
File size:458'032 bytes
First seen:2020-10-15 00:35:21 UTC
Last seen:2020-10-15 01:58:56 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash af234412c61f3039a095ae3e4a9a73d6 (6 x IcedID)
ssdeep 6144:fp8UAO6FESk1R9RI2YHGJ5/l1CDoJg3vtcRQYJHxaL8vdS+:fp8UBSY9mHGJ5/lwDFcGYJRBvP
Threatray 438 similar samples on MalwareBazaar
TLSH 5AA45C01B6E18034F4F316F949BE52689B3D7EA01B2494DF52C12DED8A35EE0AD31B67
Reporter malware_traffic
Tags:dll IcedID Shathak TA551

Intelligence


File Origin
# of uploads :
2
# of downloads :
133
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Launching the default Windows debugger (dwwin.exe)
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
4 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2020-10-15 00:37:06 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
trojan banker family:icedid
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Blacklisted process makes network request
IcedID First Stage Loader
ServiceHost packer
IcedID, BokBot
Unpacked files
SH256 hash:
ab037590458a18587639666fe8a6b68e64b2bcae099df9c3b631e3ed4be1ce20
MD5 hash:
eb3bef5498794d476a91588715d0397f
SHA1 hash:
76a91430be5dd3f5904e70881a13939e3fcc8769
SH256 hash:
2af54f4e4afa320ba4f34cdf5b7306e23a26d2605f3fb5d6f0b0791f458d8b4d
MD5 hash:
f2d44be5bc74f6bfed6ef6eaaddd7b2e
SHA1 hash:
4030e1c53a6df7b695bb8dd56943d4faddb51d6f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments