🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ddbf709d25b00e5bdc9635953ea39af16cae7bfbf066db394f7068eb3bef90c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1ddbf709d25b00e5bdc9635953ea39af16cae7bfbf066db394f7068eb3bef90c
SHA3-384 hash: 1b451f32e99d8ccc269d372011b5aeaa34e6e31e72f0a8c88fb54135265ef045133b6bc9ad36bfefc037fa7bfd64efe4
SHA1 hash: 1a27e42b97a295f3f9c7d1e2518ad22e9e83e81e
MD5 hash: d84b34312cbddcd18a3c13305e694019
humanhash: glucose-idaho-twenty-beer
File name:ETS_0100026_067831106.xll
Download: download sample
Signature Dridex
File size:6'144 bytes
First seen:2021-11-22 14:05:29 UTC
Last seen:2021-11-22 15:49:32 UTC
File type:Excel file xll
MIME type:application/x-dosexec
imphash 310601ec00bee298c3bcae9ebec13f72 (1 x Formbook, 1 x Dridex)
ssdeep 96:Z1fNK1eu7F95VWYmMYmDciIoCbkFwS9nFV7bz4XCLQ7oxL:DNmeqF9TWYmMjDciIoCbkqS9j734SMo
Threatray 21 similar samples on MalwareBazaar
TLSH T128C18453BA64CDD3D4181339B89371258C2DAB27EE59621F249520CEBBEE2D94C393E4
Reporter adrian__luca
Tags:Dridex xll

Intelligence


File Origin
# of uploads :
2
# of downloads :
152
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
ETS_0100026_067831106.xll
Verdict:
No threats detected
Analysis date:
2021-11-22 20:52:16 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Threat name:
Win64.Downloader.Tnega
Status:
Malicious
First seen:
2021-11-18 12:43:43 UTC
File Type:
PE+ (Dll)
AV detection:
24 of 45 (53.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Dridex

Excel file xll 1ddbf709d25b00e5bdc9635953ea39af16cae7bfbf066db394f7068eb3bef90c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments