MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7a5135fb78a58682cc0de111468bb007d1f8c78bbd561d3f155809b6e991a29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b7a5135fb78a58682cc0de111468bb007d1f8c78bbd561d3f155809b6e991a29
SHA3-384 hash: 1ddd5db145fe976df4abf08c8b8b0704120f53015424df797bc5fa3209d37853d80163650f18159face6d9481f9e9a57
SHA1 hash: 66559a0612c114a829d4ac609efd50b592be9ed6
MD5 hash: 7132d826975660b78ac7479482e89b4e
humanhash: georgia-two-florida-lithium
File name:tw5ljof.zip
Download: download sample
Signature Dridex
File size:940'032 bytes
First seen:2020-10-26 16:28:58 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 2705154d91afe869ffd4a33eb8f95728 (1 x Dridex)
ssdeep 12288:PTpv7UgV1uWl2vci23zIA2Fch1WKCRTFtwmP/FZFVn6VxUfHVtpaaSl/p+szMZNL:bpbrK+zyFiJCRXN56VxC1tCTqMUl
Threatray 46 similar samples on MalwareBazaar
TLSH 801501527BD2E478C066993ACE99C4FD861ABE06DE34086B34C07F5F3E365514E38E29
Reporter Anonymous
Tags:Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
3 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2020-10-26 15:47:39 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader evasion trojan discovery family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Checks installed software on the system
Checks whether UAC is enabled
Blacklisted process makes network request
Dridex Loader
Dridex
Malware Config
C2 Extraction:
85.207.13.169:443
74.207.242.13:1688
176.58.101.200:49160
164.132.75.129:3388
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll b7a5135fb78a58682cc0de111468bb007d1f8c78bbd561d3f155809b6e991a29

(this sample)

Comments