MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11d6703c422ba5ff6cbc0f40c5099a283dfd70fed43d1265366a4919201c6ce0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 11d6703c422ba5ff6cbc0f40c5099a283dfd70fed43d1265366a4919201c6ce0
SHA3-384 hash: f8b9618a994b6753c55fd8d543210abe66b89040ef8935e708b117519275081a1a56724c726dd5a484a89f5be86ba321
SHA1 hash: 3edc2c3cbd1cd08b5e34b21433e5658e81f99f0d
MD5 hash: c8ec2aee1e6b3b1aa46f5c6dcf9c7110
humanhash: red-triple-spaghetti-romeo
File name:c8ec2aee1e6b3b1aa46f5c6dcf9c7110.dll
Download: download sample
Signature Dridex
File size:327'680 bytes
First seen:2020-09-27 07:51:30 UTC
Last seen:2020-09-27 08:37:53 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 2ba9fdebd2889a2f1b35f1c626ccd0ae (2 x Dridex)
ssdeep 6144:OaM65wVpzY9WKgRP2Ba6k0UwLBlZtR7ynoOyzzR42eAgA:OffY0P2BfxjhOQe67
Threatray 75 similar samples on MalwareBazaar
TLSH 3264E03922E94109F1B75FF0E93888066DE9BCA17E7EC1AC6B111C1D5A23914DCF87E6
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
224
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-09-23 23:48:06 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Dridex Loader
Dridex
Malware Config
C2 Extraction:
151.236.219.181:443
142.4.6.57:14043
162.144.127.197:3786
103.40.116.68:5443
Unpacked files
SH256 hash:
11d6703c422ba5ff6cbc0f40c5099a283dfd70fed43d1265366a4919201c6ce0
MD5 hash:
c8ec2aee1e6b3b1aa46f5c6dcf9c7110
SHA1 hash:
3edc2c3cbd1cd08b5e34b21433e5658e81f99f0d
SH256 hash:
aa9218047c2dfee4d766c6bae5c98e9aa253e055d4248c78bd957224f15787a3
MD5 hash:
f9b0fa5c115ab0991361c9586430f4ab
SHA1 hash:
8bbb72f9bec981c05dea90b3b4d9939a959d8794
SH256 hash:
d9405516d908f39043c9971884df73b57ae6db3002364444ec9b4e2a1d026ddb
MD5 hash:
ec143ee5d90b68fea6a3b2fa68217fa9
SHA1 hash:
dcf9dc94a9e4760af9350f3d3bf32781c4c5d236
Detections:
win_dridex_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 11d6703c422ba5ff6cbc0f40c5099a283dfd70fed43d1265366a4919201c6ce0

(this sample)

  
Delivery method
Distributed via web download

Comments