🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eca3ef27738569bbd0d4b577da6848068769e8164d7b3276c4867f3343a8c948. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: eca3ef27738569bbd0d4b577da6848068769e8164d7b3276c4867f3343a8c948
SHA3-384 hash: 2a1f164ec3b42579abeba6ded0c5f2d0d716cf1ee002a85520e66479c1be59ef0a344e46b97faba7f38bee4d0d0c41eb
SHA1 hash: 17806b97e908d7ab562e49a6a3583132abee5706
MD5 hash: 972114244ef633551cd0eac54e17f144
humanhash: oklahoma-edward-illinois-indigo
File name:Unpaid_3945_Oct31.html
Download: download sample
Signature IcedID
File size:251'507 bytes
First seen:2022-10-31 14:29:13 UTC
Last seen:Never
File type: html
MIME type:text/html
ssdeep 6144:QVSATLIqgaQHpV3kvjSem3N/DkSf3Yx1VJSxt+ooYum:ADTLyOjoAK3Yx3JSxcY3
TLSH T10E34120D7B62920C9E1A43653C5B8918F9B9E9937EA0054B56AAF07B3D5CE12C40FFB1
Reporter k3dg3___
Tags:533886235 html IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
415
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
HtmlDropper
Detection:
malicious
Classification:
troj
Score:
48 / 100
Signature
Yara detected Html Dropper
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 734407 Sample: Unpaid_3945_Oct31.html Startdate: 31/10/2022 Architecture: WINDOWS Score: 48 34 Yara detected Html Dropper 2->34 8 chrome.exe 18 8 2->8         started        11 chrome.exe 2->11         started        process3 dnsIp4 22 192.168.2.1 unknown unknown 8->22 24 192.168.2.22 unknown unknown 8->24 26 239.255.255.250 unknown Reserved 8->26 13 unarchiver.exe 4 8->13         started        15 chrome.exe 8->15         started        process5 dnsIp6 18 7za.exe 2 13->18         started        28 clients.l.google.com 142.250.147.102, 443, 49704 GOOGLEUS United States 15->28 30 142.250.147.104, 443, 49742 GOOGLEUS United States 15->30 32 4 other IPs or domains 15->32 process7 process8 20 conhost.exe 18->20         started       
Threat name:
Document-HTML.Trojan.IcedID
Status:
Malicious
First seen:
2022-10-31 14:30:08 UTC
File Type:
Text (HTML)
Extracted files:
6
AV detection:
8 of 25 (32.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:QbotStuff
Author:anonymous
Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

IcedID

html eca3ef27738569bbd0d4b577da6848068769e8164d7b3276c4867f3343a8c948

(this sample)

2ff819c01e03fa26413bf607711df3e5a7f4efdffe55f57c3c637d6c7b408bec

  
Dropping
SHA256 2ff819c01e03fa26413bf607711df3e5a7f4efdffe55f57c3c637d6c7b408bec
  
Delivery method
Distributed via e-mail attachment

Comments