🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e6a2e75a6b2a3f2ac324ed063728d53dd0ff40e24e2abe11a725c41a54aabfe9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 5


Intelligence 5 IOCs YARA 6 File information Comments

SHA256 hash: e6a2e75a6b2a3f2ac324ed063728d53dd0ff40e24e2abe11a725c41a54aabfe9
SHA3-384 hash: ddced7832a81fc4244b9468c341b5ed3c659555f2e9aed307aeea0b0e5aea15323929c19f938b6cf16a5159d97c817b0
SHA1 hash: ece067f744b35128b1ab6e0ddc142263ede1c3bd
MD5 hash: 88c823ff377b101e6f948f3f34b467c5
humanhash: pasta-xray-fish-white
File name:Document_OF62.iso
Download: download sample
Signature IcedID
File size:438'272 bytes
First seen:2022-11-10 23:52:48 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:dd1Im48xJjSbUhI77ETb+JS+lDDWbOrL/ZslDP/w+lDxlDuSTjQBRlDFKLEzbrbU:r1ImVJj0Rfyg7QKbuGiKpw9
TLSH T19A94A913A7481332C5A702746B4F6BD6B338947C772AC660509EC1397386C7997BFAE8
TrID 99.4% (.NULL) null bytes (2048000/1)
0.2% (.ISO) ISO 9660 CD image (5100/59/2)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter proxylife
Tags:426369791 IcedID iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
229
Origin country :
AE AE
File Archive Information

This file archive contains 6 file(s), sorted by their relevance:

File name:disparager.txt
File size:105'334 bytes
SHA256 hash: 3ec5cd405a7726ce26f8b6c7db99b272d237ec884c66d1a10e72db01a54c819e
MD5 hash: 2650e51879baf81c728b6a7b1e3efd1d
MIME type:text/plain
Signature IcedID
File name:forties.txt
File size:175'120 bytes
SHA256 hash: d6e4322185e113b3660633634d79c95faa7ad3a67f6b488d2ce0f04763cf56ce
MD5 hash: 9bacba341f7a20f65356db6971e3ba7a
MIME type:text/plain
Signature IcedID
File name:anyhow.tmp
File size:93'696 bytes
SHA256 hash: 64598e2bc1c0f58636825193c93405d555a5fcd87816ec22842125629d3136ad
MD5 hash: 13563c9b38c5aa0e0efbd7b3fbbbb32d
MIME type:application/x-dosexec
Signature IcedID
File name:sinus.cmd
File size:275 bytes
SHA256 hash: 0e56587cbdddd1851d2db510d6a539bc325029bc55e66a9d2cd9f011125b12b8
MD5 hash: fd0220a4dd09b7ae925c622720d1d834
MIME type:text/plain
Signature IcedID
File name:Document.lnk
File size:1'253 bytes
SHA256 hash: 2709e19c5241ec78b7852bcd78498884a2a1147e0273a194fd235f62cdc786cc
MD5 hash: 5285072bd147d8b3c46337442c45d6f6
MIME type:application/octet-stream
Signature IcedID
File name:coleman.cmd
File size:182 bytes
SHA256 hash: f0357b0a99f1dd3a389c18768f38863f949cb8d79cf71d0273ee9875ce88ab7e
MD5 hash: 079f76e0ebf45dd46b4c5a7cf6eac2dd
MIME type:text/plain
Signature IcedID
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
masquerade
Threat name:
Win32.Trojan.Woreflint
Status:
Malicious
First seen:
2022-11-10 23:53:09 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
3 of 40 (7.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:426369791 banker loader trojan
Behaviour
Enumerates physical storage devices
Malware Config
C2 Extraction:
ahilacarstrupert.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:iso_lnk
Author:tdawg
Rule name:Qakbot_IsoCampaign
Author:Malhuters
Description:Qakbot New Campaign ISO
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:SUSP_VBS_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contain VBS functions
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments