MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bbadde28126494cb587eae843c7febcdbd0b1bd67bba5213ca0d4e6a1d58e0d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bbadde28126494cb587eae843c7febcdbd0b1bd67bba5213ca0d4e6a1d58e0d6
SHA3-384 hash: d45aa23faa416c32c45657ed69e5310f125115ca118c8be408eef5b6d30aaf240c9aef30c9ff755fd7efe50b1f9d944a
SHA1 hash: 51634687591f8ef7b8019dce3f7d53b07fa0e00a
MD5 hash: b9700382f9f54280c0d3a10aecd62b53
humanhash: sixteen-jersey-xray-mockingbird
File name:temp.tmp
Download: download sample
Signature IcedID
File size:458'032 bytes
First seen:2020-10-15 01:45:22 UTC
Last seen:2020-10-15 03:03:43 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash af234412c61f3039a095ae3e4a9a73d6 (6 x IcedID)
ssdeep 6144:fp8UAO6FESk1R9RI2YHGJ5/l1CDoJg3vtcRQYJHxaL8vdS/:fp8UBSY9mHGJ5/lwDFcGYJRBvS
Threatray 444 similar samples on MalwareBazaar
TLSH 16A45C01B6E18034F4F316F949BE52689B3D7EA01B2494DF52C12DED8A35EE0AD31B67
Reporter malware_traffic
Tags:dll IcedID Shathak TA551

Intelligence


File Origin
# of uploads :
2
# of downloads :
146
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Launching the default Windows debugger (dwwin.exe)
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 298389 Sample: temp.tmp Startdate: 15/10/2020 Architecture: WINDOWS Score: 48 12 Multi AV Scanner detection for submitted file 2->12 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 9 6->8         started        10 WerFault.exe 3 9 6->10         started       
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2020-10-15 01:47:04 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
trojan banker family:icedid
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Blacklisted process makes network request
IcedID First Stage Loader
ServiceHost packer
IcedID, BokBot
Unpacked files
SH256 hash:
db4a35ce71dde5f3f1979bf7a7ad49a31b4ff098e340db335d5cbf0e60040908
MD5 hash:
faa6ed2c666e5f2732e2f2e9753fda17
SHA1 hash:
9f90a9af01461006ae6f3e5875d1f94d9920764c
SH256 hash:
bbadde28126494cb587eae843c7febcdbd0b1bd67bba5213ca0d4e6a1d58e0d6
MD5 hash:
b9700382f9f54280c0d3a10aecd62b53
SHA1 hash:
51634687591f8ef7b8019dce3f7d53b07fa0e00a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments