🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b371a9165a5aba71ba38d8ddd6d25b72ccde8f0803a225c5a2502c54c7660cfc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b371a9165a5aba71ba38d8ddd6d25b72ccde8f0803a225c5a2502c54c7660cfc
SHA3-384 hash: 4c760277881775d936fb75ec9d2d316f1fd3775a190c44143779a65e3975a4720dc8de214de7613b0de936753d62525a
SHA1 hash: 73618070c587ccd8c2d5db1b0e9dff9c9752721d
MD5 hash: 2d950809af05e59e861896e4a85d4920
humanhash: queen-oxygen-steak-tennessee
File name:123567890.dll
Download: download sample
Signature IcedID
File size:605'518 bytes
First seen:2023-06-27 11:46:19 UTC
Last seen:2023-06-27 12:05:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e9ef9b3a65dd6bf58caf965b2eb31e2f (9 x IcedID)
ssdeep 6144:aQsPjChP/DWxDmFKP9VCUMrex0Ai/k8XFRFj75GE39OXaz:Bs7Rx6FKP9Vyp175p9OXaz
Threatray 1 similar samples on MalwareBazaar
TLSH T150D47B8AEBC1DC6BC41503B04DDB9725273AF498A383DF4B27A495382C6376A7F8564C
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter JAMESWT_WT
Tags:dll exe IcedID

Intelligence


File Origin
# of uploads :
3
# of downloads :
357
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
123567890.dll
Verdict:
No threats detected
Analysis date:
2023-06-27 11:12:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
MeasuringTime
EvasionQueryPerformanceCounter
EvasionGetTickCount
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
anti-debug lolbin masquerade overlay
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
5 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
b371a9165a5aba71ba38d8ddd6d25b72ccde8f0803a225c5a2502c54c7660cfc
MD5 hash:
2d950809af05e59e861896e4a85d4920
SHA1 hash:
73618070c587ccd8c2d5db1b0e9dff9c9752721d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments