🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0df936105f5f5ccd9a13f4abc6b7e09cf64d8c1513e21dea87883201aacbabe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b0df936105f5f5ccd9a13f4abc6b7e09cf64d8c1513e21dea87883201aacbabe
SHA3-384 hash: ad17785250ff6ef0f378ff54804e6dc3216de0a618edd11e4c9ea3aa3042aa707e648f6b9d0ca83a33da909d8e9c8d01
SHA1 hash: 57568cea1f2ec6f825d14993ceb12c38e9f0af86
MD5 hash: d332de88116f1767fd5b5dd1389b5369
humanhash: glucose-pasta-carpet-september
File name:INV_Copy_02_13_#99.pdf
Download: download sample
Signature IcedID
File size:47'655 bytes
First seen:2023-02-13 17:09:08 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 768:fje8aSVurhcJIDxX96mOQyfX22xEsIxVgXFTJMpqK7A5KPYAyq+KnSo2:LBurSIDxN6mOJX2k7Ie9mmM2
TLSH T10423D015E0988CE91FB69A74E047E80DB807F63787DBBB78D832A7C5B041D9A93F1191
Reporter proxylife
Tags:IcedID pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
512
Origin country :
ZW ZW
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
80%
Tags:
phishing
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
2%
Score Benign:
98%
Result
Threat name:
Qbot Downloader
Detection:
malicious
Classification:
spre.troj
Score:
52 / 100
Signature
C2 URLs / IPs found in malware configuration
Yara detected Qbot Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 806400 Sample: INV_Copy_02_13_#99.pdf Startdate: 13/02/2023 Architecture: WINDOWS Score: 52 36 Yara detected Qbot Downloader 2->36 38 C2 URLs / IPs found in malware configuration 2->38 8 chrome.exe 18 13 2->8         started        11 AcroRd32.exe 15 42 2->11         started        13 chrome.exe 2->13         started        process3 dnsIp4 34 239.255.255.250 unknown Reserved 8->34 15 unarchiver.exe 4 8->15         started        17 chrome.exe 8->17         started        20 RdrCEF.exe 68 11->20         started        process5 dnsIp6 22 7za.exe 2 15->22         started        26 www.google.com 142.250.180.132, 443, 49707, 49734 GOOGLEUS United States 17->26 28 clients.l.google.com 142.250.180.174, 443, 49704 GOOGLEUS United States 17->28 32 4 other IPs or domains 17->32 30 192.168.2.1 unknown unknown 20->30 process7 process8 24 conhost.exe 22->24         started       
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments