MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b2cbb8194e4fad7d943d4cec9899d6a3acf82e4f67ec69875d85a1b01cd7f899. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
IcedID
Vendor detections: 6
| SHA256 hash: | b2cbb8194e4fad7d943d4cec9899d6a3acf82e4f67ec69875d85a1b01cd7f899 |
|---|---|
| SHA3-384 hash: | 0f586e128b92798fd7751646db6bf7c50d96fcb80182443b4bead32f8249d63ce9600f4b5c4423d1567be34184ce58dd |
| SHA1 hash: | 18dce0565fb1dc14965bf598b27deced67df29d1 |
| MD5 hash: | 88b114a6d58a56320607c7d23e219b4d |
| humanhash: | arkansas-louisiana-friend-india |
| File name: | Invoice_Mar_01_Scan#257.pdf |
| Download: | download sample |
| Signature | IcedID |
| File size: | 22'398 bytes |
| First seen: | 2023-03-02 09:33:55 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/pdf |
| ssdeep | 384:rokJwCfRNI9LM2shvMg+yrgKO+Xqh2n/UP9EMOZEiC41PDWjy5tEFlMqXPLKLoAa:roxCf3aMk1y82nMPSMOmiC5y0j/+8Aa |
| TLSH | T1F8A2BFBB69AAD413F44F85B8822778092517251909CB235069BC1FBFF37C9CE5E8F590 |
| Reporter | |
| Tags: | IcedID pdf pw-2746 |
Intelligence
File Origin
# of uploads :
1
# of downloads :
422
Origin country :
DEVendor Threat Intelligence
Detection(s):
Result
Verdict:
Suspicious
File Type:
PDF File
Verdict:
Unknown
Threat level:
0/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Pdf/malicious_confidence_60%
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
1%
Score Benign:
99%
Result
Threat name:
Qbot Downloader
Detection:
malicious
Classification:
spre.troj
Score:
52 / 100
Signature
C2 URLs / IPs found in malware configuration
Yara detected Qbot Downloader
Behaviour
Behavior Graph:
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.