🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 22daf83fb5df15c6da250f65f2c5e2ea0cf1aff9f44e0dddc89832a4254c6502. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 22daf83fb5df15c6da250f65f2c5e2ea0cf1aff9f44e0dddc89832a4254c6502
SHA3-384 hash: fd8ef8dd141f277e190ff3ca7c97d165ce459da0c773f0ae2e599e36ee31edba60262ee0faeceb762691cec5e92c79b5
SHA1 hash: 4d7b861c9afeb6f6c034f05898125e7b564649f7
MD5 hash: e39c5a909536c5f5131bacce8404119e
humanhash: massachusetts-oxygen-september-six
File name:Quotation copy.xll
Download: download sample
Signature Dridex
File size:71'168 bytes
First seen:2021-11-22 22:51:07 UTC
Last seen:2021-11-23 00:42:22 UTC
File type:Excel file xll
MIME type:application/x-dosexec
imphash 9edcfef623344e3e92d8f951b9d9b572 (3 x Dridex)
ssdeep 1536:LFLbGjKWkFpMNyWPIlZWMSZCjsWwcdbCBCG66j:Lp7WQMNyWPIZSYjbCBP66j
TLSH T19A635A1076D1C4B1E6BE29359430C6B59E3DBD604EE09D6B3B9A063E4F306C2D634E6B
Reporter James_inthe_box
Tags:Dridex xll

Intelligence


File Origin
# of uploads :
2
# of downloads :
150
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Quotation copy.xll
Verdict:
Suspicious activity
Analysis date:
2021-11-22 23:20:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Payload URLs
URL
File name
http://bitly.com/hsjkahwuoahnskjahkj
Office Plugin File
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
60%
Tags:
greyware
Threat name:
Win32.Trojan.Sabsik
Status:
Malicious
First seen:
2021-11-22 22:50:53 UTC
File Type:
PE (Dll)
AV detection:
25 of 44 (56.82%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Creates scheduled task(s)
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Legitimate hosting services abused for malware hosting/C2
Loads dropped DLL
Blocklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:gen_Excel_xll_addin_suspicious
Author:@JohnLaTwC
Description:Detects suspicious XLL add-ins to Excel

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments