🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2cbb8194e4fad7d943d4cec9899d6a3acf82e4f67ec69875d85a1b01cd7f899. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b2cbb8194e4fad7d943d4cec9899d6a3acf82e4f67ec69875d85a1b01cd7f899
SHA3-384 hash: 0f586e128b92798fd7751646db6bf7c50d96fcb80182443b4bead32f8249d63ce9600f4b5c4423d1567be34184ce58dd
SHA1 hash: 18dce0565fb1dc14965bf598b27deced67df29d1
MD5 hash: 88b114a6d58a56320607c7d23e219b4d
humanhash: arkansas-louisiana-friend-india
File name:Invoice_Mar_01_Scan#257.pdf
Download: download sample
Signature IcedID
File size:22'398 bytes
First seen:2023-03-02 09:33:55 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:rokJwCfRNI9LM2shvMg+yrgKO+Xqh2n/UP9EMOZEiC41PDWjy5tEFlMqXPLKLoAa:roxCf3aMk1y82nMPSMOmiC5y0j/+8Aa
TLSH T1F8A2BFBB69AAD413F44F85B8822778092517251909CB235069BC1FBFF37C9CE5E8F590
Reporter malkoegler
Tags:IcedID pdf pw-2746

Intelligence


File Origin
# of uploads :
1
# of downloads :
422
Origin country :
DE DE
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
1%
Score Benign:
99%
Result
Threat name:
Qbot Downloader
Detection:
malicious
Classification:
spre.troj
Score:
52 / 100
Signature
C2 URLs / IPs found in malware configuration
Yara detected Qbot Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 818418 Sample: Invoice_Mar_01_Scan#257.pdf Startdate: 02/03/2023 Architecture: WINDOWS Score: 52 40 Yara detected Qbot Downloader 2->40 42 C2 URLs / IPs found in malware configuration 2->42 8 chrome.exe 18 10 2->8         started        11 AcroRd32.exe 15 39 2->11         started        13 chrome.exe 2->13         started        process3 dnsIp4 36 192.168.2.4 unknown unknown 8->36 38 239.255.255.250 unknown Reserved 8->38 15 unarchiver.exe 4 8->15         started        17 chrome.exe 1 8->17         started        20 conhost.exe 8->20         started        22 RdrCEF.exe 77 11->22         started        process5 dnsIp6 24 7za.exe 2 15->24         started        28 www.google.com 142.250.203.100, 443, 49709, 49724 GOOGLEUS United States 17->28 30 accounts.google.com 142.250.203.109, 443, 49700 GOOGLEUS United States 17->30 34 3 other IPs or domains 17->34 32 192.168.2.1 unknown unknown 22->32 process7 process8 26 conhost.exe 24->26         started       
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

pdf b2cbb8194e4fad7d943d4cec9899d6a3acf82e4f67ec69875d85a1b01cd7f899

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments