MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c5c0aa62424b9f660bbbe7d6f5bf75ccd92876fff9cfd006f2ffcf8a7b141dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0c5c0aa62424b9f660bbbe7d6f5bf75ccd92876fff9cfd006f2ffcf8a7b141dd
SHA3-384 hash: 144af73b03bffebca35810087b44cdbde46381acfcfec36975d0d941928018452d4480dfedc1349de5faf76d93dfeb5e
SHA1 hash: bc126efa30a16b2e0dc3fea4988260d2a3cbb880
MD5 hash: e20634b13d1713b41d52313702e7fef3
humanhash: princess-may-cold-solar
File name:Fmdlmggi.dll
Download: download sample
Signature Dridex
File size:838'144 bytes
First seen:2020-10-27 14:59:43 UTC
Last seen:2020-10-28 06:15:26 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 257c9c5290df8ee6a2dc718c4a417e40 (1 x Dridex)
ssdeep 12288:oKl2AGp1SHu+jz+FijuodKa83fVm8iycDq0B0u8/aPzNa6r4F5I6XJM1WXuOW69e:JlAp4hFjiHVBCpQiPZVr4FuT1WJY
TLSH 4105E010BA51D039E17761B8CEAAD6FCA6297E51DF6404CB30C83FEF36359A59D3120A
Reporter James_inthe_box
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
3
# of downloads :
122
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
4 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-10-27 14:58:56 UTC
File Type:
PE (Dll)
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet discovery evasion loader trojan
Behaviour
Suspicious use of WriteProcessMemory
Checks installed software on the system
Checks whether UAC is enabled
Blacklisted process makes network request
Dridex Loader
Dridex
Malware Config
C2 Extraction:
85.207.13.169:443
74.207.242.13:1688
176.58.101.200:49160
164.132.75.129:3388
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments