🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 036f5bf868c0b64d27cab3114e173b59456c74ca670185cc417420cf2b2965d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 036f5bf868c0b64d27cab3114e173b59456c74ca670185cc417420cf2b2965d7
SHA3-384 hash: ec3bc2d803e53a29242776354ae03f968af417989b1f64b3f7bc752ae02b06d712b1ba1ca7d3fb62f08fcdad535d90ad
SHA1 hash: 2b9e0c70f6d055a7d04ec8e7826f8e2b1d70696d
MD5 hash: 6a2d48899c57d400aae8ec0d25d1fa49
humanhash: nineteen-lactose-red-jig
File name:d3dcsx_43.dll
Download: download sample
Signature Dridex
File size:192'512 bytes
First seen:2021-08-25 15:07:26 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 15d931f2533164c416970d03fa5b5c88 (10 x Dridex)
ssdeep 3072:xH0uyjZqEpAK+Gf78TBdrXkTM5vhRg9Esf0DwvtyMpVnpA+z6tX8sxKViW67dU:xUua/Pv7YNhRIEZDeXVpAxtMsxK
Threatray 4'959 similar samples on MalwareBazaar
TLSH T1F914DF82CD9F46F9C21B167139F531BE21E80605A769CC2BCADAD2FBF47D300D46261A
Reporter abuse_ch
Tags:22201 dll Dridex


Avatar
abuse_ch
Dridex payload URL:
https://files.slack.com/files-pri/T02C6AWQFPX-F02CAEANX34/download/d3dcsx_43.dll?pub_secret=60dbc2efeb

Dridex C2:
103.82.248.59:443
54.39.98.141:6602
103.109.247.8:10443

Intelligence


File Origin
# of uploads :
1
# of downloads :
713
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Found PHP interpreter
Tries to delay execution (extensive OutputDebugStringW loop)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 471599 Sample: d3dcsx_43.dll Startdate: 25/08/2021 Architecture: WINDOWS Score: 68 32 54.39.98.141 OVHFR Canada 2->32 34 103.109.247.8 IDNIC-UNUSA-AS-IDUniversitasNahdlatulUlamaSurabayaID Indonesia 2->34 36 103.82.248.59 DE-CORPDE-CORPTH Thailand 2->36 38 Found malware configuration 2->38 40 Yara detected Dridex unpacked file 2->40 42 Found PHP interpreter 2->42 44 C2 URLs / IPs found in malware configuration 2->44 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        14 rundll32.exe 9->14         started        16 cmd.exe 1 9->16         started        18 5 other processes 9->18 signatures6 46 Tries to delay execution (extensive OutputDebugStringW loop) 11->46 20 WerFault.exe 2 9 14->20         started        22 WerFault.exe 14->22         started        24 rundll32.exe 16->24         started        26 WerFault.exe 9 18->26         started        28 WerFault.exe 9 18->28         started        process7 process8 30 WerFault.exe 23 9 24->30         started       
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-08-25 15:08:20 UTC
AV detection:
18 of 27 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
103.82.248.59:443
54.39.98.141:6602
103.109.247.8:10443
Unpacked files
SH256 hash:
cbd1044de6b4dd0e2464792664276ea11cca77306a1b3897534ea4e0c86205f2
MD5 hash:
943583c7118f5a1838ca013e958441b2
SHA1 hash:
05a6fa27b474d06b4b66ab4753933b99aaece467
Detections:
win_doppeldridex_auto
SH256 hash:
036f5bf868c0b64d27cab3114e173b59456c74ca670185cc417420cf2b2965d7
MD5 hash:
6a2d48899c57d400aae8ec0d25d1fa49
SHA1 hash:
2b9e0c70f6d055a7d04ec8e7826f8e2b1d70696d
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Dridex

DLL dll 036f5bf868c0b64d27cab3114e173b59456c74ca670185cc417420cf2b2965d7

(this sample)

Comments