MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2dc73ab125bbcfcaa2ad81debaa45da08adcfe021761d04c606812bf3748df68. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2dc73ab125bbcfcaa2ad81debaa45da08adcfe021761d04c606812bf3748df68
SHA3-384 hash: fdbf13a680b8658dfc23c024d43e5ef9959480a0310099c85f28a4f5b2352f145305015b1b01b986cc263b86ff25594c
SHA1 hash: 3aa246583b5c23cf99cd29eefd85fe89c93ed9d3
MD5 hash: e5a341348ce8322f94ea8ebd0d899e2a
humanhash: wyoming-princess-equal-july
File name:2dc73ab125bbcfcaa2ad81debaa45da08adcfe021761d04c606812bf3748df68.bin
Download: download sample
Signature Dridex
File size:249'856 bytes
First seen:2020-09-23 14:06:00 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 1e514447f004e9505dc193777ba8a65d (6 x Dridex)
ssdeep 3072:cGH53A7kiOzJfpjPFO5k8Rbp9ieXF7AdJhCScQHltiVAjc77zOaYNk55xqKTi:3sMTUb7AFc7WTWq
TLSH E7349F67E68390F2CD4324726C2F2BBBF730042145349AE6E7F19DBA9937AD19329750
Reporter JAMESWT_WT
Tags:Dridex


Avatar
JAMESWT_WT
@ Arkbird_SOLG

Intelligence


File Origin
# of uploads :
1
# of downloads :
158
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 289151 Sample: XYLEiWS6DC.bin Startdate: 23/09/2020 Architecture: WINDOWS Score: 56 25 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->25 27 Multi AV Scanner detection for submitted file 2->27 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 regsvr32.exe 8->12         started        process5 14 iexplore.exe 11 83 10->14         started        process6 16 iexplore.exe 5 162 14->16         started        dnsIp7 19 edge.gycpi.b.yahoodns.net 87.248.118.22, 443, 49736, 49737 YAHOO-DEBDE United Kingdom 16->19 21 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49738, 49739 FASTLYUS United States 16->21 23 12 other IPs or domains 16->23
Threat name:
Win32.Trojan.Bluteal
Status:
Malicious
First seen:
2020-09-23 14:06:40 UTC
File Type:
PE (Dll)
AV detection:
11 of 29 (37.93%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
Score:
  10/10
Tags:
botnet loader family:dridex
Behaviour
Dridex Loader
Dridex family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments