🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e519b8b79c30ff05cba6b43dc9a6bb03f715c053bb0e8e50abed123cf4f7f9ef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: e519b8b79c30ff05cba6b43dc9a6bb03f715c053bb0e8e50abed123cf4f7f9ef
SHA3-384 hash: 83de81cd5f6142c3e70d4412ea0049d59b5f0666bf5c8e04fef61eb127a93b452fe184239a78f44537d0e2d4e38e8eec
SHA1 hash: d4f21faaefd382c4089146c43eefb0f1458337d1
MD5 hash: 1bb92c333fa5c1e2b18934f05fac6e51
humanhash: orange-diet-bravo-louisiana
File name:Setup_Win_31-12-2022_01-50-16.zip
Download: download sample
Signature IcedID
File size:469'723 bytes
First seen:2022-12-31 01:55:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Pluss5FqDiw24ZqUnZfahtdOmqL6Nu6jcwSZsmk4dhIfi8L:PUh50Diw2lustd0L6Nv9SZsZ4AfDL
TLSH T1DBA423F0CE9E62DE3AA8870759D298C9360F856D3E9433D49BC7D8F5E9C02D4682146F
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:IcedID zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
150
Origin country :
IE IE
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup_Win_31-12-2022_01-50-16.msi
File size:790'528 bytes
SHA256 hash: c0a063352598eae28f226207503d864a06f5490497b074a9390927793ea16bfd
MD5 hash: 4509edb7effdfc57e288bb7b23fa0180
MIME type:application/x-msi
Signature IcedID
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed packed rundll32.exe
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2022-12-31 01:56:10 UTC
File Type:
Binary (Archive)
Extracted files:
33
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:2957048208 banker loader trojan
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Enumerates connected drives
Checks computer location settings
Loads dropped DLL
Blocklisted process makes network request
IcedID, BokBot
Malware Config
C2 Extraction:
whothitheka.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments