🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da10da7db6553074fe3de65c53de86972b6441df91109ccc2dd8f5172fc38899. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: da10da7db6553074fe3de65c53de86972b6441df91109ccc2dd8f5172fc38899
SHA3-384 hash: 91408cec77c3b396a46dffad608948faa7080209352a66a1d3497857355cbe6b6e569344008497b87464be4245a8e4a1
SHA1 hash: 836e6b889d3133dd828e9b3701ec2846b65e5651
MD5 hash: 84347a026ff8c8e0168f28cf62bd5691
humanhash: skylark-uncle-ack-vegan
File name:Document_09_13_617.zip
Download: download sample
Signature IcedID
File size:11'367 bytes
First seen:2023-09-14 11:28:20 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:x1YpBtEeaFKAbrWnRl9A1sHeIbrQikdazB/N634T/G3mrhmWzOTk42raB0PRQkNu:xgBCeaFKAbqRM15YNkdazEW/sm/t4OaD
TLSH T14A32BFD5148B242C9FBFE8F39DA49DFE7E0025C72C4144A9C544A58A6FC186977CAA82
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:1638996626 IcedID laurellkhamilton-shubhmishra-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
165
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Document_09_13_617.js
File size:45'469 bytes
SHA256 hash: 9bb9e0d33d74a56fa1eeaea35fe0c0791303c2f81ea61d1c91a9a5c08f3f1bb7
MD5 hash: 4bc2420ce8f7d9a440b8e79e8fc6832a
MIME type:text/plain
Signature IcedID
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive lolbin lolbin obfuscated replace rundll32
Threat name:
Script-JS.Trojan.IcedID
Status:
Malicious
First seen:
2023-09-14 11:29:04 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
9 of 22 (40.91%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:1638996626 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Downloads MZ/PE file
IcedID, BokBot
Malware Config
C2 Extraction:
minutozhart.online
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments