🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcea01bcdf759e26eb5644b31931af24eff447062976e3936827c86c34bd563e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: dcea01bcdf759e26eb5644b31931af24eff447062976e3936827c86c34bd563e
SHA3-384 hash: 5c0dfddeb217336c34feda74448568abfdf74664e68aad459087f9b4998900fe9aec29eaf93acea616e00bff89f3b91f
SHA1 hash: a008afd82797fe3b1acb23232666862c8c2867fa
MD5 hash: ad60bae464b7de29cdc7cd00cd7cf806
humanhash: network-utah-lake-artist
File name:04993758883.dll
Download: download sample
Signature IcedID
File size:605'529 bytes
First seen:2023-06-27 12:06:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e9ef9b3a65dd6bf58caf965b2eb31e2f (9 x IcedID)
ssdeep 6144:aQsPjChP/DWxDmFKP9VCUMrex0Ai/k8XFRFj75GX39OXaP:Bs7Rx6FKP9Vyp175y9OXaP
Threatray 4 similar samples on MalwareBazaar
TLSH T146D47B8AEBC1DC6BC41503B04DDB9725273AF498A383DF4B27A495382C6376A7F8564C
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter JAMESWT_WT
Tags:dll exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
373
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
04993758883.dll
Verdict:
No threats detected
Analysis date:
2023-06-27 12:07:07 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
MeasuringTime
EvasionQueryPerformanceCounter
EvasionGetTickCount
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
anti-debug lolbin masquerade overlay
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
5 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
dcea01bcdf759e26eb5644b31931af24eff447062976e3936827c86c34bd563e
MD5 hash:
ad60bae464b7de29cdc7cd00cd7cf806
SHA1 hash:
a008afd82797fe3b1acb23232666862c8c2867fa
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments