MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1003e3179583d7694d8bd7fbbe1fae629ac71cbef35a260a2288f600876b6bdc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 1003e3179583d7694d8bd7fbbe1fae629ac71cbef35a260a2288f600876b6bdc
SHA3-384 hash: 34bc59b2d175655078b0a6a4ddabb7398f1f168e7998415bc88ad2a0725e19ac37b105fbc018c666e671663be616ede8
SHA1 hash: 42adc3e30608a553857aaeb2c5ad9e94e26c3faf
MD5 hash: fed8c11efafe66f7c098489abb8a572c
humanhash: freddie-may-lion-april
File name:zd0pccrar
Download: download sample
Signature Dridex
File size:331'776 bytes
First seen:2020-09-09 10:12:31 UTC
Last seen:2020-09-09 12:56:12 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 2cab58e57e2dc442524d4dc15c61cdab (3 x Dridex)
ssdeep 6144:xzUaMVbo0KJkrc7vmGzMB5Xps+62b1NR+1Njo1N/Q1N2xA:VUa2nKyrc7vDoBta+7ZNRQNjiN/qNSA
Threatray 58 similar samples on MalwareBazaar
TLSH 7264D04163EB204DF4BFBFF2A4798245ACBE7C958438455DE320085F42BA2B6895EF71
Reporter JAMESWT_WT
Tags:Dridex

Intelligence


File Origin
# of uploads :
3
# of downloads :
178
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-09-09 10:14:07 UTC
File Type:
PE (Dll)
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Dridex Loader
Dridex
Malware Config
C2 Extraction:
67.213.75.205:443
186.103.215.157:33443
185.201.9.197:9443
108.175.9.22:33443
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 1003e3179583d7694d8bd7fbbe1fae629ac71cbef35a260a2288f600876b6bdc

(this sample)

  
Delivery method
Distributed via web download

Comments