🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4ea6aec4f71e0a39407bdf76f00d3e6bcce95f01bef35fada84717b3cf6dc1c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: c4ea6aec4f71e0a39407bdf76f00d3e6bcce95f01bef35fada84717b3cf6dc1c
SHA3-384 hash: fc0c843379eb8d891ca8cea75cca1a3c6508eb7d00d58a47d58ff9353606cabe5e39ef326640572406d995d7733f5a5f
SHA1 hash: 73658a7e655716e22713c0c842aa1ccc73c6bff9
MD5 hash: 08fe8c55de15a15dd4583255fb5d6a68
humanhash: stream-march-connecticut-hot
File name:udagqoaw3.dll
Download: download sample
Signature IcedID
File size:196'984 bytes
First seen:2023-08-12 09:33:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a56f115ee5ef2625bd949acaeec66b76 (57 x PureHVNC, 57 x Stealc, 36 x CoinMiner)
ssdeep 6144:jZU+Q0/Xns9tMKN1fPRqTBNB8nX/A2JpiF69:jS+Q289tMw18B8nppiF69
Threatray 1 similar samples on MalwareBazaar
TLSH T167144A2EB2F294ADD9A7C13045BB81316D31FC751B30DA2F27D4EB350F22E20965AE65
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.6% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter JAMESWT_WT
Tags:exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
379
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
udagqoaw3.dll
Verdict:
No threats detected
Analysis date:
2023-08-12 09:36:14 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Gathering data
Malware family:
IcedID Core Loader
Verdict:
Malicious
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
84 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected IcedID
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1290457 Sample: udagqoaw3.dll.exe Startdate: 12/08/2023 Architecture: WINDOWS Score: 84 19 Found malware configuration 2->19 21 Malicious sample detected (through community Yara rule) 2->21 23 Antivirus detection for URL or domain 2->23 25 3 other signatures 2->25 7 loaddll64.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 conhost.exe 7->13         started        15 8 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2023-08-12 09:25:13 UTC
File Type:
PE+ (Dll)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
7677ded3858e5e1864584c4b041c568052b8aca58cacfed8836dfdbc7c466ada
MD5 hash:
5abd355726f77c06133d3bd7f7856558
SHA1 hash:
de750f33a7d88759e71833dd90e25f5b53daf46d
Detections:
IcedIDCoreLoader
SH256 hash:
c4ea6aec4f71e0a39407bdf76f00d3e6bcce95f01bef35fada84717b3cf6dc1c
MD5 hash:
08fe8c55de15a15dd4583255fb5d6a68
SHA1 hash:
73658a7e655716e22713c0c842aa1ccc73c6bff9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:crime_win64_photoloader_packed
Author:Rony (@r0ny_123)
Description:Detects specific packed photoloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments