MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa8e5817b7a1e2a8129b1c6df41ccc378b6e44372de4c27edba38d6a9d1d40d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



IcedID


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fa8e5817b7a1e2a8129b1c6df41ccc378b6e44372de4c27edba38d6a9d1d40d1
SHA3-384 hash: cb1e1e19ec8614a05a62d776728d251565f8a26c24f97075ff93fa03eb5835587efcb2b5163058d3c9f5e829c5b8e6c5
SHA1 hash: 2c560ff85da953d326c99d26b4688c4553dcb37a
MD5 hash: 01de124cfce46ee08b17cee79487f63a
humanhash: island-venus-twenty-missouri
File name:fa8e5817b7a1e2a8129b1c6df41ccc378b6e44372de4c27edba38d6a9d1d40d1
Download: download sample
Signature IcedID
File size:282'624 bytes
First seen:2020-03-23 18:54:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a67ae384240e6fde305f0e394ffe0ee3 (1 x IcedID)
ssdeep 3072:Mjj2vK7AAn1oAlj04oE8igTOshgHhLOEYyCJTO7zGqu9EJix9h7HkeAE+SKBNXXO:/vE9ows2HhL37D43h7uJSeJ0i
Threatray 144 similar samples on MalwareBazaar
TLSH 7E549D1131E2C076E6F3267A4465DBB54A7BB8225B355ACF6BC40ABD9F246D08B3130F
Reporter Marco_Ramilli
Tags:exe IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

IcedID

Executable exe fa8e5817b7a1e2a8129b1c6df41ccc378b6e44372de4c27edba38d6a9d1d40d1

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleOutputW
KERNEL32.dll::WriteConsoleA
KERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetConsoleCtrlHandler
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleOutputCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA

Comments