🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c118816fa2545af9989e8f4d5a444e4ad65925ed4fb1e63bf5710dadd0216c9d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c118816fa2545af9989e8f4d5a444e4ad65925ed4fb1e63bf5710dadd0216c9d
SHA3-384 hash: e4477d5241921f15663517f3baaad134d0dcb5dd9eb435825a3820a3e4dc190fde35e6b378d66cb4afd699d521a9864d
SHA1 hash: dad0eb40919abd5cc88adf764d7120c107afbed0
MD5 hash: 2ca8a95954a9b6e2e36cb8ce0fe87525
humanhash: illinois-thirteen-indigo-ceiling
File name:Scan_34332_INV.pdf
Download: download sample
Signature IcedID
File size:107'369 bytes
First seen:2023-01-17 12:29:39 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:d4SKMR6INFFcdo9ZrPqjiPvLgCk2uRBD5y49:gMR6IuduZTqO3LXkRzy49
TLSH T1FBA3F198AFB03ECBFEE66D360991E50D27CC9825831BD3815235839A7C17F856B4385B
Reporter adrian__luca
Tags:IcedID pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
420
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
icedid
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
2%
Score Benign:
98%
Result
Threat name:
Qbot Downloader
Detection:
malicious
Classification:
spre.troj
Score:
52 / 100
Signature
C2 URLs / IPs found in malware configuration
Yara detected Qbot Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 785756 Sample: Scan_34332_INV.pdf Startdate: 17/01/2023 Architecture: WINDOWS Score: 52 35 Yara detected Qbot Downloader 2->35 37 C2 URLs / IPs found in malware configuration 2->37 9 AcroRd32.exe 15 45 2->9         started        process3 process4 11 chrome.exe 18 8 9->11         started        14 RdrCEF.exe 72 9->14         started        dnsIp5 31 239.255.255.250 unknown Reserved 11->31 16 unarchiver.exe 4 11->16         started        18 chrome.exe 11->18         started        33 192.168.2.1 unknown unknown 14->33 process6 dnsIp7 21 7za.exe 2 16->21         started        25 accounts.google.com 142.250.180.173, 443, 49700 GOOGLEUS United States 18->25 27 clients.l.google.com 142.250.184.46, 443, 49699 GOOGLEUS United States 18->27 29 3 other IPs or domains 18->29 process8 process9 23 conhost.exe 21->23         started       
Threat name:
Document-PDF.Trojan.IcedID
Status:
Malicious
First seen:
2023-01-17 12:30:13 UTC
File Type:
Document
Extracted files:
2
AV detection:
9 of 26 (34.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

pdf c118816fa2545af9989e8f4d5a444e4ad65925ed4fb1e63bf5710dadd0216c9d

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments