🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b02f1bd4d7e80e9948544fc7b38d6736a04a7a3f360bb60e5e0b165f66a4a325. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: b02f1bd4d7e80e9948544fc7b38d6736a04a7a3f360bb60e5e0b165f66a4a325
SHA3-384 hash: 16ff2853d730b2cf3433702565d53286cb6fb44cfbc9f83993f77794625729956daa0049867720d1e9c3b02cfee4a420
SHA1 hash: 7377c27d3517a789e03038ca54fe23b9d3ca0c17
MD5 hash: bb16ffb6d50e82f5d98f192548e05e77
humanhash: wisconsin-xray-colorado-hamper
File name:redacted-bd-file-10.04.2022.html
Download: download sample
Signature IcedID
File size:1'680'378 bytes
First seen:2022-10-04 15:32:02 UTC
Last seen:Never
File type: html
MIME type:text/html
ssdeep 24576:kRN3k60YPkcFKiZDpB1Uz41XscofkhMjSatFPuNL0Knq9v6WFU8Qz0+vjiNoCllj:Ma60G5NdZHROmOKEqr+
TLSH T11B7533411DA1AE09C998927C307B1F2A3B101E65180699D2BBB979EB170FFE3530FC78
TrID 62.5% (.SMI/SMIL) Synchronized Multimedia Integration Language (5001/2/2)
37.4% (.HTML) HyperText Markup Language (3000/1/1)
Reporter k3dg3___
Tags:140125615 html IcedID TA551

Intelligence


File Origin
# of uploads :
1
# of downloads :
285
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

html b02f1bd4d7e80e9948544fc7b38d6736a04a7a3f360bb60e5e0b165f66a4a325

(this sample)

a930c4e91e95095ece02d7458c0ebcf911c31e6d82fe53432c5ea121a6cdc930

  
Dropping
SHA256 a930c4e91e95095ece02d7458c0ebcf911c31e6d82fe53432c5ea121a6cdc930
  
Delivery method
Distributed via e-mail attachment

Comments