MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba0743df409f0176c11637524ea85cda7da7d0e36d5f2b0c7614c2d70f0a533a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs 1 YARA 9 File information Comments

SHA256 hash: ba0743df409f0176c11637524ea85cda7da7d0e36d5f2b0c7614c2d70f0a533a
SHA3-384 hash: 248ce24502e1d6dffbcf09c4ac0210f5c2541f5b8bb6bc9221a4dccc128283013abab9bb65251123047bf5ed2ceac90c
SHA1 hash: 294a376fd9c816869028d4f72d38967c041d621a
MD5 hash: 2ed64d980cc773b019b8d114ba413163
humanhash: michigan-spring-yankee-bulldog
File name:Setup_Win_24-01-2023_17-01-52.zip
Download: download sample
Signature IcedID
File size:878'483 bytes
First seen:2023-01-24 17:30:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:Cw3D57Q9xcjANZeSxYl833AzGVllBI/eXetBoEfDcsoZ4IX7PMnNTD7rt6xE+S0O:931QHISp3AY02XaBDc9eNTHx6T2
TLSH T1A01512BCA43277C6C14FD0B12AF8AFF80BB8ECB219667AC5592DD21D8DC614F6815E05
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter malware_traffic
Tags:BokBot file-pumped IcedID zip

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
druidfenixis.com https://threatfox.abuse.ch/ioc/1073923/

Intelligence


File Origin
# of uploads :
1
# of downloads :
164
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup_Win_24-01-2023_17-01-50.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:734'356'064 bytes
SHA256 hash: e4623bb4e1a8f69af039fcb3d30a24cad0ff7822b1189a7fe9b0da74f26f226c
MD5 hash: 6908aa1c9f661ffd4d904a7bc1505c74
De-pumped file size:342'016 bytes (Vs. original size of 734'356'064 bytes)
De-pumped SHA256 hash: 3de8568bc332a346e9a87f9f360c4b1942ba48c2c5ed655e8a2a608fa67d498d
De-pumped MD5 hash: 2a11a124eb354924c974b9497e673182
MIME type:application/x-dosexec
Signature IcedID
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:3324185820 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
IcedID, BokBot
Malware Config
C2 Extraction:
druidfenixis.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:crime_win32_icedid_stage1
Author:Rony (@r0ny_123)
Description:Detects IcedID photoloader
Reference:https://sysopfb.github.io/malware,/icedid/2020/04/28/IcedIDs-updated-photoloader.html
Rule name:IcedIDLoader
Author:kevoreilly, threathive, enzo
Description:IcedID Loader
Rule name:IcedID_init_loader
Author:@bartblaze
Description:Identifies IcedID (stage 1 and 2, initial loaders).
Rule name:MALWARE_Win_IceID
Author:ditekSHen
Description:Detects IceID / Bokbot variants
Rule name:Windows_Trojan_IcedID_0b62e783
Author:Elastic Security
Rule name:Windows_Trojan_IcedID_48029e37
Author:Elastic Security
Rule name:Windows_Trojan_IcedID_91562d18
Author:Elastic Security
Rule name:win_photoloader_a0
Author:Daniel Plohmann
Description:Detects win.photoloader.
Rule name:win_photoloader_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.photoloader.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments