MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d03b19d0605914065009b9ba9acecc5d8c7c74e5af47e141d2ce10b50c79ed0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 0d03b19d0605914065009b9ba9acecc5d8c7c74e5af47e141d2ce10b50c79ed0
SHA3-384 hash: 66c22dbe705575150e898a1f8c1a36bee8426785a623f82fbd1ac0d4b69f27d0f5e0467decbe75dc6ac20dfb7a6d370c
SHA1 hash: 376cb6f60a8fc1809a63ef716fdd9afe17176c54
MD5 hash: be9aeabcd1c893b9dde6dfdf747ad6bf
humanhash: virginia-floor-gee-alanine
File name:be9aeabcd1c893b9dde6dfdf747ad6bf.dll
Download: download sample
Signature Dridex
File size:360'448 bytes
First seen:2021-01-03 10:58:11 UTC
Last seen:2021-01-03 12:41:39 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 6144:JkbSx0/H8bVMlt7sQaB2XqLYHfcf2B2q7fEInukz2:Hx68bilhsQryYo246fEIuE2
Threatray 25 similar samples on MalwareBazaar
TLSH B374F168C9E798EAE83BC071F75D81B8316B2E985B371BD6CD7BA219595300F084E50F
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
342
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 335590 Sample: nRzq7Wys0B.dll Startdate: 03/01/2021 Architecture: WINDOWS Score: 23 10 Machine Learning detection for sample 2->10 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 6 9 6->8         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-01-03 10:59:05 UTC
AV detection:
22 of 47 (46.81%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
0d03b19d0605914065009b9ba9acecc5d8c7c74e5af47e141d2ce10b50c79ed0
MD5 hash:
be9aeabcd1c893b9dde6dfdf747ad6bf
SHA1 hash:
376cb6f60a8fc1809a63ef716fdd9afe17176c54
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 0d03b19d0605914065009b9ba9acecc5d8c7c74e5af47e141d2ce10b50c79ed0

(this sample)

  
Delivery method
Distributed via web download

Comments