🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5498dbfd2efefc4acc9ab9773d4fcbedeffa57e5a7d5d72398b86c7af93bd20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 3


Intelligence 3 IOCs YARA 5 File information Comments

SHA256 hash: f5498dbfd2efefc4acc9ab9773d4fcbedeffa57e5a7d5d72398b86c7af93bd20
SHA3-384 hash: 10304ef4107729f0e51a9643196ed0da5b93e1fd219a2d35e2af4a2b102ec97bf1eeae35305bd1cd841faeb260ab9e77
SHA1 hash: c385c5360898e6ea5e18dcb9406020c43a1964b3
MD5 hash: 7885bed0fed2e032be6a79067886788d
humanhash: neptune-romeo-west-gee
File name:Scan_134_INV_01-24.zip
Download: download sample
Signature IcedID
File size:531'140 bytes
First seen:2023-01-24 17:41:44 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 84925
ssdeep 12288:KeXvpdCHYGLa9BISHHYo722gvpoYWzjBsDqNGyWGszReXL70th:nXxY4GmfHHYI2x8ls24GX77W
TLSH T108B4239C660557452232A024EEC93EB7E47EC29869DEEE1B800EC5C24D74227B7E367D
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:1691396905 IcedID pw-84925 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
148
Origin country :
BR BR
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:PITCHPOT.DAT
File size:1'086'464 bytes
SHA256 hash: 95ad74c1dff5293c49c955a4e77c17e6912c7b8d1fc8f5f4c6f05ac77a56a9ab
MD5 hash: a146dac7b641fff2c5c3c0cf320731aa
MIME type:application/x-dosexec
Signature IcedID
File name:LUGGAGES.LNK
File size:1'800 bytes
SHA256 hash: 77ed0dccd237b248c1ad2f0eccc4e4ac97417f6d5b1367ee489ff441d8100eca
MD5 hash: 601b3a5450d6e5eaaa98d6e57cdb8ba5
MIME type:application/octet-stream
Signature IcedID
File name:BURGOYNE.CMD
File size:528 bytes
SHA256 hash: 8ab55cd0615654a37d58dec772fef116884cad834618a88b1f217b1be58a7303
MD5 hash: 366dba7e80f19a7ecbe07594a419e369
MIME type:text/x-msdos-batch
Signature IcedID
Vendor Threat Intelligence
Gathering data
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2023-01-24 18:12:05 UTC
File Type:
Binary (Archive)
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments