🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa1660ea0078a96b031d319d151d6c7b6b2c0319c12e46ab5f48b2574fe22e1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: fa1660ea0078a96b031d319d151d6c7b6b2c0319c12e46ab5f48b2574fe22e1e
SHA3-384 hash: b7b0363e4745b74bd4b3676096a9aa1196731df2851c745060b3afc46af99f013b63b0927f629a497e18af2d7353cbe2
SHA1 hash: 7d1781fcdc3625704ea63247f41a7af70b87b1d0
MD5 hash: a812728c98d9bfb34914f3fb110db534
humanhash: tennis-pasta-hotel-kansas
File name:electrotyping.dat
Download: download sample
Signature IcedID
File size:233'864 bytes
First seen:2023-01-17 14:26:32 UTC
Last seen:2023-01-17 16:35:08 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 4c03145cfbf96dbd374588743143bfc3 (2 x IcedID)
ssdeep 6144:y6sbYTf1IFpSQjAfK67TbDkJGvPiaTB00CS2:jNf60h0JGSaTn2
Threatray 1'299 similar samples on MalwareBazaar
TLSH T18F349D46F6701CB1ECB780B8C6E6851BD7B2745A1394C34F87A8C7A62F1B7607A4C396
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter abuse_ch
Tags:dat exe IcedID

Intelligence


File Origin
# of uploads :
2
# of downloads :
244
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Setup_Win_16-01-2023_20-01-20.zip
Verdict:
Suspicious activity
Analysis date:
2023-01-16 20:05:21 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
icedid overlay packed
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
5 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.IcedID
Status:
Malicious
First seen:
2023-01-16 20:10:53 UTC
File Type:
PE+ (Dll)
AV detection:
10 of 26 (38.46%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
fa1660ea0078a96b031d319d151d6c7b6b2c0319c12e46ab5f48b2574fe22e1e
MD5 hash:
a812728c98d9bfb34914f3fb110db534
SHA1 hash:
7d1781fcdc3625704ea63247f41a7af70b87b1d0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:SPLCrypt
Author:James Quinn, Binary Defense
Description:Identifies SPLCrypt, a new crypter associated with Bazaloader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments