MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 11
| SHA256 hash: | 2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba |
|---|---|
| SHA3-384 hash: | ee1fc513b031180e8a9ff603e81886ef294505ec925ac16b34b60cc72c611bb1d0502a1217209738e2f1b1e2f5d08477 |
| SHA1 hash: | 615681fa42bd7551960185f299983017270721f6 |
| MD5 hash: | 532a0d3f4883d39d8fb6bc59213c1cca |
| humanhash: | venus-louisiana-juliet-december |
| File name: | SecuriteInfo.com.Trojan.Dridex.777.2559.26925 |
| Download: | download sample |
| Signature | Dridex |
| File size: | 443'240 bytes |
| First seen: | 2021-11-22 20:57:03 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 056c904cbd1371f4cd9591217dcabf76 (27 x Dridex) |
| ssdeep | 6144:LdNaq9pIe91oA9f+G91Yu9Vg09T8W9pSo91yqj1Ks910W9KY2qjYwVdJltMf694p:X/JbTxxPDlLwaYwVdJEy+y6 |
| Threatray | 5'444 similar samples on MalwareBazaar |
| TLSH | T19F94BF968AD3A103F3FA7E7C42753E9D9E31782921989EF8CDA399FA5C7800411C54F6 |
| Reporter | |
| Tags: | dll Dridex signed |
Code Signing Certificate
| Organisation: | STAND ALONE MUSIC LTD |
|---|---|
| Issuer: | Sectigo RSA Code Signing CA |
| Algorithm: | sha256WithRSAEncryption |
| Valid from: | 2020-12-07T00:00:00Z |
| Valid to: | 2021-12-07T23:59:59Z |
| Serial number: | 3b777165b125bccc181d0bac3f5b55b3 |
| Intelligence: | 55 malware samples on MalwareBazaar are signed with this code signing certificate |
| MalwareBazaar Blocklist: | This certificate is on the MalwareBazaar code signing certificate blocklist (CSCB) |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | f680fab6a9d21e8e76003c5c28b3c5084866d7ac85cf0cfb5aaa02f69ee99f1e |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
86.107.98.232:8333
188.165.214.166:4664
144.91.110.219:9217
Unpacked files
e4198e5ddd3476159870472005baefe077ad89d64c5336de69822dba48e0bd14
8d95894beb03202d4905bbe434a17f11a765271e6b6e7c1e9c2d7ebad3cd084d
819fc6af6dcb82b1af116f823834b11cf2fe81decd62c4416d547baf4e893fc7
ac71a3dd1d22803f1f2eaf491c30e2ffd551eede6a85f43d2e04076e1c676cd6
e7c32603420fbce56a655f49901fc305fe6996968e772198b323d2cf479e0d0a
1d0e26f69497f3bf8f5bc25caff90759f4c6d03677636b94f44d91b49df881a5
b8555144c432f6402fbd1f63babf819e01cecfa91ae767efcecc38980b82f457
5981abf8d99ddc7aeb5cf7947b95e55c1dc01d635e2594970ca750019843b2a4
cac710c68dbb70d01d55e9f255bbe90d0295cd132957d79646c84363909b8184
2e37eaf9308b3e4fca68af55062166607a13c17c5326d09105285a4339c9c5ee
d865b2599871231a2c80953a5f2025cf421add331a339afc43b9191862d5e5e4
6c0255b197f194b9d4a9c2563402968b25db9fb3701e96e0384132972f4b9f7b
4bb2e867507fc5ebe843cc93909ef1add4e713b87bd92354b5e4d89dd475795f
c30c3c7ec2d99c156f2aa2e2f1af6757c869a17bce28033dcbdbeb643138eb62
02af89b2418919f9e7cb01dd80aa400327db454150699e2ea0deab8dfa0fc5ed
32f17c1a85ac961dfb2e335c9d064bb76131af31d7d2f91be2402a460cdeb632
f257aca4990d750cff5fb9bf30fbb8f86586faec2b63715a763ed490faa5e5c4
5615baf7d9a6a82ad581e3a24164899cf67f103504da16c04bb31809e5f1ceac
2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba
5cf7006d0348806011f54c999dbb90d6490b78d6ab65af5043a98ae1aafec6ce
bf4eb49615032b3d912f691a7d5cfbae4c4d95070ef5e1a4ef53afbe6a619e15
6dcea6bb5658e7228b21588f48658502bc67824953f2e78ee7a25d5fe2291e45
013e64f21efff937b65e069dc9c07760166a96d3e0cd318c91f94e66ae76c536
1f5fe1bb3c3f0c9c09eb0d9a794f284b57f9945707864710e20b7cbe16297d1b
d01da7616bb72f4988a3e62066586c5fc135b8380468d7bbc463a7ebc9964d3a
4a246227c6e8b90ca664792a9d6ced9f1e7c20283891bbb722623ba17aa266de
b8555144c432f6402fbd1f63babf819e01cecfa91ae767efcecc38980b82f457
2e37eaf9308b3e4fca68af55062166607a13c17c5326d09105285a4339c9c5ee
2baa13d604c8ed8e387c4624f13e43d76f560c1f9cd2d9d1cd90eacc9d4e22ba
d01da7616bb72f4988a3e62066586c5fc135b8380468d7bbc463a7ebc9964d3a
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DridexLoader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 dropper C2 parsing function |
| Rule name: | DridexV4 |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 Payload |
| Rule name: | dridex_loader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex Loader |
| Rule name: | MALWARE_Win_DLLLoader |
|---|---|
| Author: | ditekSHen |
| Description: | Detects unknown DLL Loader |
| Rule name: | Sectigo_Code_Signed |
|---|---|
| Description: | Detects code signed by the Sectigo RSA Code Signing CA |
| Reference: | https://bazaar.abuse.ch/export/csv/cscb/ |
| Rule name: | Sectigo_Code_Signed |
|---|---|
| Description: | Detects code signed by the Sectigo RSA Code Signing CA |
| Reference: | https://bazaar.abuse.ch/export/csv/cscb/ |
| Rule name: | win_doppeldridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.doppeldridex. |
| Rule name: | win_dridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.dridex. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.