🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb22aa2565e6bbb36f0eca44232cd2415e9348790a5f47c7c549d4bcf5399e78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 2


Intelligence 2 IOCs YARA 6 File information Comments

SHA256 hash: cb22aa2565e6bbb36f0eca44232cd2415e9348790a5f47c7c549d4bcf5399e78
SHA3-384 hash: f5e7644847b3475b0e90b75018352cbe72a07d75db571434b05cfa234bce6411e45c69bee87a158aa3976a99cc1ef7dc
SHA1 hash: ac1fe535302f1124659740367be6d572903e366a
MD5 hash: 15f40ab253052f2a727b759b3f0377a2
humanhash: victor-kitten-cold-solar
File name:Document_72.zip
Download: download sample
Signature IcedID
File size:191'931 bytes
First seen:2023-01-20 15:09:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 54275
ssdeep 3072:+gPR5mpvL9eDiLuqod0VQu5e2sMfn34MjPdnciXeNOXjDK3Fw4T849:i95LzDV51sMffzRmNOTIT8w
TLSH T10414238BD6C180A90F5B78906CE03E771304FA4E70766257D83B5EE1BCA9767850DDE2
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:886885680 IcedID pw-54275 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
136
Origin country :
IE IE
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:pamphleteering.dat
File size:526'336 bytes
SHA256 hash: ad174760985c5418b4a3c3a97cd8d7658e3bbb7030f72f2eff9ff97e57f200bd
MD5 hash: 0b44756101b2f2a79341c08bfebbaf46
MIME type:application/x-dosexec
Signature IcedID
File name:sacsimsapI.cmd
File size:1'625 bytes
SHA256 hash: 7f66918d6312cce66eb7d7c8027477f488e567c2483694e2bc77104423b5d386
MD5 hash: 946edfa955e469aad87a33035cf28586
MIME type:text/plain
Signature IcedID
File name:Scan_01-20.lnk
File size:1'978 bytes
SHA256 hash: 19c6557ae51b7322ad35b35cf4729fc98521a1b99b0f9bb14d39defe4e2a0e09
MD5 hash: 0b7b3668c7c6a12cdc41c45dc5ecf28b
MIME type:application/octet-stream
Signature IcedID
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments