🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA 8 File information Comments

SHA256 hash: 2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba
SHA3-384 hash: ee1fc513b031180e8a9ff603e81886ef294505ec925ac16b34b60cc72c611bb1d0502a1217209738e2f1b1e2f5d08477
SHA1 hash: 615681fa42bd7551960185f299983017270721f6
MD5 hash: 532a0d3f4883d39d8fb6bc59213c1cca
humanhash: venus-louisiana-juliet-december
File name:SecuriteInfo.com.Trojan.Dridex.777.2559.26925
Download: download sample
Signature Dridex
File size:443'240 bytes
First seen:2021-11-22 20:57:03 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 056c904cbd1371f4cd9591217dcabf76 (27 x Dridex)
ssdeep 6144:LdNaq9pIe91oA9f+G91Yu9Vg09T8W9pSo91yqj1Ks910W9KY2qjYwVdJltMf694p:X/JbTxxPDlLwaYwVdJEy+y6
Threatray 5'444 similar samples on MalwareBazaar
TLSH T19F94BF968AD3A103F3FA7E7C42753E9D9E31782921989EF8CDA399FA5C7800411C54F6
Reporter SecuriteInfoCom
Tags:dll Dridex signed

Code Signing Certificate

Organisation:STAND ALONE MUSIC LTD
Issuer:Sectigo RSA Code Signing CA
Algorithm:sha256WithRSAEncryption
Valid from:2020-12-07T00:00:00Z
Valid to:2021-12-07T23:59:59Z
Serial number: 3b777165b125bccc181d0bac3f5b55b3
Intelligence: 55 malware samples on MalwareBazaar are signed with this code signing certificate
MalwareBazaar Blocklist:This certificate is on the MalwareBazaar code signing certificate blocklist (CSCB)
Thumbprint Algorithm:SHA256
Thumbprint: f680fab6a9d21e8e76003c5c28b3c5084866d7ac85cf0cfb5aaa02f69ee99f1e
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Tries to delay execution (extensive OutputDebugStringW loop)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 526815 Sample: SecuriteInfo.com.Trojan.Dri... Startdate: 23/11/2021 Architecture: WINDOWS Score: 72 41 188.165.214.166 OVHFR France 2->41 43 67.207.95.35 DIGITALOCEAN-ASNUS United States 2->43 45 2 other IPs or domains 2->45 49 Found malware configuration 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 Yara detected Dridex unpacked file 2->53 55 C2 URLs / IPs found in malware configuration 2->55 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        14 rundll32.exe 9->14         started        16 rundll32.exe 9->16         started        18 4 other processes 9->18 signatures6 57 Tries to delay execution (extensive OutputDebugStringW loop) 11->57 20 WerFault.exe 9 11->20         started        22 WerFault.exe 14->22         started        25 WerFault.exe 14->25         started        27 WerFault.exe 2 9 16->27         started        29 WerFault.exe 16->29         started        31 rundll32.exe 18->31         started        33 WerFault.exe 9 18->33         started        35 WerFault.exe 18->35         started        37 2 other processes 18->37 process7 dnsIp8 47 192.168.2.1 unknown unknown 22->47 39 WerFault.exe 23 9 31->39         started        process9
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-11-22 20:04:27 UTC
File Type:
PE (Dll)
AV detection:
21 of 27 (77.78%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22204 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
67.207.95.35:443
86.107.98.232:8333
188.165.214.166:4664
144.91.110.219:9217
Unpacked files
SH256 hash:
c93601e415690601f36f63c3874fbbc8238b79edd41144c4613179553f27e5a7
MD5 hash:
f64c80e162621fa0795553541e0ca2f1
SHA1 hash:
219bbf90e6291dbb19022e27edcd755b3ced54b0
Detections:
win_dridex_auto
Parent samples :
44a307cc9cad880c85fab734a2bc59b2b66c7785786d79b9a2a72bcd0e736f35
e4198e5ddd3476159870472005baefe077ad89d64c5336de69822dba48e0bd14
8d95894beb03202d4905bbe434a17f11a765271e6b6e7c1e9c2d7ebad3cd084d
819fc6af6dcb82b1af116f823834b11cf2fe81decd62c4416d547baf4e893fc7
ac71a3dd1d22803f1f2eaf491c30e2ffd551eede6a85f43d2e04076e1c676cd6
e7c32603420fbce56a655f49901fc305fe6996968e772198b323d2cf479e0d0a
1d0e26f69497f3bf8f5bc25caff90759f4c6d03677636b94f44d91b49df881a5
b8555144c432f6402fbd1f63babf819e01cecfa91ae767efcecc38980b82f457
5981abf8d99ddc7aeb5cf7947b95e55c1dc01d635e2594970ca750019843b2a4
cac710c68dbb70d01d55e9f255bbe90d0295cd132957d79646c84363909b8184
2e37eaf9308b3e4fca68af55062166607a13c17c5326d09105285a4339c9c5ee
d865b2599871231a2c80953a5f2025cf421add331a339afc43b9191862d5e5e4
6c0255b197f194b9d4a9c2563402968b25db9fb3701e96e0384132972f4b9f7b
4bb2e867507fc5ebe843cc93909ef1add4e713b87bd92354b5e4d89dd475795f
c30c3c7ec2d99c156f2aa2e2f1af6757c869a17bce28033dcbdbeb643138eb62
02af89b2418919f9e7cb01dd80aa400327db454150699e2ea0deab8dfa0fc5ed
32f17c1a85ac961dfb2e335c9d064bb76131af31d7d2f91be2402a460cdeb632
f257aca4990d750cff5fb9bf30fbb8f86586faec2b63715a763ed490faa5e5c4
5615baf7d9a6a82ad581e3a24164899cf67f103504da16c04bb31809e5f1ceac
2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba
5cf7006d0348806011f54c999dbb90d6490b78d6ab65af5043a98ae1aafec6ce
bf4eb49615032b3d912f691a7d5cfbae4c4d95070ef5e1a4ef53afbe6a619e15
6dcea6bb5658e7228b21588f48658502bc67824953f2e78ee7a25d5fe2291e45
013e64f21efff937b65e069dc9c07760166a96d3e0cd318c91f94e66ae76c536
1f5fe1bb3c3f0c9c09eb0d9a794f284b57f9945707864710e20b7cbe16297d1b
d01da7616bb72f4988a3e62066586c5fc135b8380468d7bbc463a7ebc9964d3a
4a246227c6e8b90ca664792a9d6ced9f1e7c20283891bbb722623ba17aa266de
SH256 hash:
2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba
MD5 hash:
532a0d3f4883d39d8fb6bc59213c1cca
SHA1 hash:
615681fa42bd7551960185f299983017270721f6
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:dridex_loader
Author:kevoreilly
Description:Dridex Loader
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:Sectigo_Code_Signed
Description:Detects code signed by the Sectigo RSA Code Signing CA
Reference:https://bazaar.abuse.ch/export/csv/cscb/
Rule name:Sectigo_Code_Signed
Description:Detects code signed by the Sectigo RSA Code Signing CA
Reference:https://bazaar.abuse.ch/export/csv/cscb/
Rule name:win_doppeldridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppeldridex.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba

(this sample)

  
Delivery method
Distributed via web download

Comments