MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1ddbf709d25b00e5bdc9635953ea39af16cae7bfbf066db394f7068eb3bef90c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 6
| SHA256 hash: | 1ddbf709d25b00e5bdc9635953ea39af16cae7bfbf066db394f7068eb3bef90c |
|---|---|
| SHA3-384 hash: | 1b451f32e99d8ccc269d372011b5aeaa34e6e31e72f0a8c88fb54135265ef045133b6bc9ad36bfefc037fa7bfd64efe4 |
| SHA1 hash: | 1a27e42b97a295f3f9c7d1e2518ad22e9e83e81e |
| MD5 hash: | d84b34312cbddcd18a3c13305e694019 |
| humanhash: | glucose-idaho-twenty-beer |
| File name: | ETS_0100026_067831106.xll |
| Download: | download sample |
| Signature | Dridex |
| File size: | 6'144 bytes |
| First seen: | 2021-11-22 14:05:29 UTC |
| Last seen: | 2021-11-22 15:49:32 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 310601ec00bee298c3bcae9ebec13f72 (1 x Formbook, 1 x Dridex) |
| ssdeep | 96:Z1fNK1eu7F95VWYmMYmDciIoCbkFwS9nFV7bz4XCLQ7oxL:DNmeqF9TWYmMjDciIoCbkqS9j734SMo |
| Threatray | 21 similar samples on MalwareBazaar |
| TLSH | T128C18453BA64CDD3D4181339B89371258C2DAB27EE59621F249520CEBBEE2D94C393E4 |
| Reporter | |
| Tags: | Dridex xll |
Intelligence
File Origin
# of uploads :
2
# of downloads :
152
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
ETS_0100026_067831106.xll
Verdict:
No threats detected
Analysis date:
2021-11-22 20:52:16 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Threat name:
Win64.Downloader.Tnega
Status:
Malicious
First seen:
2021-11-18 12:43:43 UTC
File Type:
PE+ (Dll)
AV detection:
24 of 45 (53.33%)
Threat level:
3/5
Detection(s):
Malicious file
Verdict:
malicious
Similar samples:
+ 11 additional samples on MalwareBazaar
Result
Malware family:
n/a
Score:
10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.30
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.