MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c94fe7b646b681ac85756b4ce7f85f4745a7b505f1a2215ba8b58375238bad10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: c94fe7b646b681ac85756b4ce7f85f4745a7b505f1a2215ba8b58375238bad10
SHA3-384 hash: d7dc3f3abf0680823bd4e24b516f9bc521b260cbffdb585d995532eb3e7f6cf9a07f96a6ec4fe3a027d379188d01f5b8
SHA1 hash: 1fc59fbf692f690b9fe82cfafc9dcbd5aac31a68
MD5 hash: 925da3a10f7dde802c8d87047b14fda6
humanhash: artist-spaghetti-lithium-zebra
File name:iec56w4ibovnb4wc.onion_Library__Dridex__dridexDroppedVBS.bin.malw
Download: download sample
Signature Dridex
File size:143'360 bytes
First seen:2020-03-18 22:02:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b10a33e794d5d2de180070d9dcc93422 (1 x Dridex)
ssdeep 3072:X9z9zjy6WEba5uuoLPhiVF3NT5nNpytoQE:X9J9gu0td5nN4
Threatray 110 similar samples on MalwareBazaar
TLSH 96E3F200E7CB61EAF8AB1C34501A586F7678EB2ECB49DCB2DB047D77D76A643C0A1950
Reporter ov3rflow1
Tags:Dridex malw

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad.spre.
Score:
92 / 100
Behaviour
Behavior Graph:
n/a
Gathering data
Threat name:
Win32.Trojan.Dridex
Status:
Malicious
First seen:
2018-02-05 17:49:35 UTC
File Type:
PE (Exe)
AV detection:
28 of 30 (93.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
MULTIMEDIA_APICan Play MultimediaWINMM.dll::midiInGetDevCapsA
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::CreatePrivateObjectSecurityEx
WIN_BASE_IO_APICan Create FilesADVAPI32.dll::OpenBackupEventLogA
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::GetUserNameA

Comments