🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f03c8309871bae2c0f09b1aa2a6f47bc2534cde3ff5170a448d4f8c52ae7d7c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 2


Intelligence 2 IOCs 1 YARA File information Comments

SHA256 hash: f03c8309871bae2c0f09b1aa2a6f47bc2534cde3ff5170a448d4f8c52ae7d7c1
SHA3-384 hash: 6a9daabc7ba5e08719d016fadaea993e4efc2c445e4964b5fa6e0dacf69d6cc515ff2baef18576177508b9e3f6f2a0c6
SHA1 hash: 768819ea843226d75b2000221132ebca84a0222c
MD5 hash: 1feec1eae3f396f0481a42fd6a8fa344
humanhash: hamper-oklahoma-finch-lion
File name:Scan_Invoice_12-09%23100.zip
Download: download sample
Signature IcedID
File size:439'609 bytes
First seen:2022-12-10 05:15:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: u753
ssdeep 12288:Zl4YHVokUNmKvdla4w3NXo9Sd7NwxYUNoYw1xhot0QM6:ZlDok2mKv/azooqxYFpZoz
TLSH T1EB9423758023AAFD986665FF9DD69802EF19D10F4FBF1F4A89A74609CC1CA1C0D98BC1
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter malware_traffic
Tags:BokBot broskabrwaf.com IcedID pw u753 zip

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
broskabrwaf.com https://threatfox.abuse.ch/ioc/1033907/

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Scan_Invoice_12-09#100.msi
File size:843'776 bytes
SHA256 hash: a5f81b3f092a05dc7026957e5d716e5976a38b152d1823ac76b84e189aa4a75b
MD5 hash: 8a0f5061861085e50d4b9e65e00244d6
MIME type:application/x-msi
Signature IcedID
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments