MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd0bb23a35eaeb24dd86a89a614ac17f330a164fcb0182c4da0b191b7be3f52d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bd0bb23a35eaeb24dd86a89a614ac17f330a164fcb0182c4da0b191b7be3f52d
SHA3-384 hash: c2bed3542f71b25a5c10bcb543ce64477acec349697ccbc73fde467e3b01d13b6afe144c9152abf8a9b604516b8f8d64
SHA1 hash: 53df00832403f2684706c4b73c6afb0cedba343a
MD5 hash: dd9b4d3c68436d27c6a912bc30adfb2e
humanhash: cup-yankee-vermont-moon
File name:temp.tmp
Download: download sample
Signature IcedID
File size:458'032 bytes
First seen:2020-10-15 00:50:55 UTC
Last seen:2020-10-15 01:58:58 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash af234412c61f3039a095ae3e4a9a73d6 (6 x IcedID)
ssdeep 6144:fp8UAO6FESk1R9RI2YHGJ5/l1CDoJg3vtcRQYJHxaL8vdSG:fp8UBSY9mHGJ5/lwDFcGYJRBvz
Threatray 440 similar samples on MalwareBazaar
TLSH 49A45C01B6E18034F4F316F949BE52689B3D7EA01B2494DF52C12DED8A35EE0AD31B67
Reporter malware_traffic
Tags:dll IcedID Shathak TA551

Intelligence


File Origin
# of uploads :
2
# of downloads :
129
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Launching the default Windows debugger (dwwin.exe)
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
5 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2020-10-15 00:52:08 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
trojan banker family:icedid
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Program crash
Blacklisted process makes network request
IcedID First Stage Loader
ServiceHost packer
IcedID, BokBot
Unpacked files
SH256 hash:
bd0bb23a35eaeb24dd86a89a614ac17f330a164fcb0182c4da0b191b7be3f52d
MD5 hash:
dd9b4d3c68436d27c6a912bc30adfb2e
SHA1 hash:
53df00832403f2684706c4b73c6afb0cedba343a
SH256 hash:
18a9abc18dec0c90380ec8a27e2ae95056a389ea481da55fad052086a255b2a6
MD5 hash:
6226bb4ec0a950abf527a5ae0e1bc8b8
SHA1 hash:
874df544c25327a42d6573f7a332477cca69a33b
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments