🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 035b872c1cb731d6df2dfea0c269828c3687c4e543c66d4803d85591f1272f4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 035b872c1cb731d6df2dfea0c269828c3687c4e543c66d4803d85591f1272f4c
SHA3-384 hash: bbd4b3ce2a861ac1786a3754afc7bc66e891a853bf5ab9ddc1fd128b618b59cfc6ad6d0fa3a913f8fcecf0095a8049a7
SHA1 hash: ea0e39259a0bdd8a237bed914356aa5e4b564f42
MD5 hash: 2a891556a1a126eecdca310bd88fe0c0
humanhash: salami-arkansas-december-oxygen
File name:2a891556a1a126eecdca310bd88fe0c0.dll
Download: download sample
Signature Dridex
File size:192'512 bytes
First seen:2021-09-22 18:08:18 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash bc9115da123ae49443de76ad96ad8e1a (7 x Dridex)
ssdeep 3072:8wd4sevPYabz9RLhPO8f3zRCyvD6meTuxn2ZjflxomQYIE5XbiK/n1:BsvQabz9C21Pmb82xnwiX
Threatray 5'017 similar samples on MalwareBazaar
TLSH T10E14D013A6B931D3E19B383F92A1E7B16E386F43C338C45BD6D4F46899312A354A5332
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
247
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Tries to delay execution (extensive OutputDebugStringW loop)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 488307 Sample: g7BtWqsSBy.dll Startdate: 22/09/2021 Architecture: WINDOWS Score: 72 38 148.251.190.18 HETZNER-ASDE Germany 2->38 40 45.73.148.28 FIBERNET-DIRECTUS United States 2->40 42 202.157.177.65 EXBCOID-AS-APPTEXABYTESNETWORKINDONESIAID Malaysia 2->42 44 Found malware configuration 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected Dridex unpacked file 2->48 50 C2 URLs / IPs found in malware configuration 2->50 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        14 rundll32.exe 9->14         started        16 cmd.exe 1 9->16         started        18 4 other processes 9->18 signatures6 52 Tries to delay execution (extensive OutputDebugStringW loop) 11->52 20 WerFault.exe 9 11->20         started        22 WerFault.exe 14->22         started        24 WerFault.exe 14->24         started        26 rundll32.exe 16->26         started        28 WerFault.exe 2 9 18->28         started        30 WerFault.exe 9 18->30         started        32 WerFault.exe 18->32         started        34 2 other processes 18->34 process7 process8 36 WerFault.exe 23 9 26->36         started       
Threat name:
Win32.Trojan.KryptikAGen
Status:
Malicious
First seen:
2021-09-22 16:10:59 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
148.251.190.18:443
45.73.148.28:10933
202.157.177.65:5412
Unpacked files
SH256 hash:
d89de08bf12232ddd89ab6677c1a2c068f86fb44a081989298b44be121693ba4
MD5 hash:
72f8e97d67a22ff67d6d5f54d3a073e0
SHA1 hash:
8ac2560ed577ef02a33dbc24e67cf5aaf74e5328
Detections:
win_doppeldridex_auto
SH256 hash:
035b872c1cb731d6df2dfea0c269828c3687c4e543c66d4803d85591f1272f4c
MD5 hash:
2a891556a1a126eecdca310bd88fe0c0
SHA1 hash:
ea0e39259a0bdd8a237bed914356aa5e4b564f42
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 035b872c1cb731d6df2dfea0c269828c3687c4e543c66d4803d85591f1272f4c

(this sample)

Comments