MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd5e9385b277e4105fe2eeb100fa9b6946016b9484b5f4901429a9e71885e5f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: dd5e9385b277e4105fe2eeb100fa9b6946016b9484b5f4901429a9e71885e5f3
SHA3-384 hash: 1fefdc5b82299f59d00a9da96d90d63e95832721c912fe912d094caff82d424b9765be380e745338faad2148d965f4fb
SHA1 hash: 5bed5f7bc2566200b1fc68d8c67c09f3a1093e33
MD5 hash: ec98fdb3d5cea2f1d78fc998275751d5
humanhash: one-vegan-victor-wisconsin
File name:dd5e9385b277e4105fe2eeb100fa9b6946016b9484b5f4901429a9e71885e5f3
Download: download sample
Signature IcedID
File size:638'256 bytes
First seen:2020-10-16 11:14:24 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 6ef7836a6671d0ad5e22fe6aeac47460 (1 x IcedID)
ssdeep 6144:6r0YImQJYDnWAAjIr8ValIBfIdHuEd+krtqg8ZdOp/qB+:6r0YIviDn1ZOfIFuEdBP8nOpi+
Threatray 765 similar samples on MalwareBazaar
TLSH 2ED40EA0FB2195B4F89781795936D9321717BE56EE6028DF008B362DDA233B254F2D0F
Reporter JAMESWT_WT
Tags:FABO SP Z O O IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
127
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
DNS request
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2020-10-15 01:16:00 UTC
File Type:
PE (Dll)
Extracted files:
13
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Blacklisted process makes network request
Unpacked files
SH256 hash:
dd5e9385b277e4105fe2eeb100fa9b6946016b9484b5f4901429a9e71885e5f3
MD5 hash:
ec98fdb3d5cea2f1d78fc998275751d5
SHA1 hash:
5bed5f7bc2566200b1fc68d8c67c09f3a1093e33
SH256 hash:
cc970fb66ffeb1004bc31bb5c08567f284bb278a93b9587f2fcd1b7f04bbd4c2
MD5 hash:
12a4f0630ac27dd1758baf71f4000aeb
SHA1 hash:
aa32b7f77566a2bd017f02f40894bea5dec24a5f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments