MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31d883327033b6efb446e9416952c638152072095e6fbfab537b74bee477b6ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 31d883327033b6efb446e9416952c638152072095e6fbfab537b74bee477b6ca
SHA3-384 hash: 3d9deeefa2582511880c476a437a0583ab5eba2000cd1713b0228e400879c35af173fdfdb96700033adfc4e133ebdb8e
SHA1 hash: bbfb63b922408ff7a3390da07c94885145371b40
MD5 hash: ce85500cad88257b43d84cda7cc264fa
humanhash: fanta-november-johnny-august
File name:ce85500cad88257b43d84cda7cc264fa.dll
Download: download sample
Signature Dridex
File size:331'776 bytes
First seen:2020-09-27 07:48:34 UTC
Last seen:2020-09-27 08:37:43 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 76ca4b0770cd5a3fae865eb520597417 (6 x Dridex)
ssdeep 6144:bud7KJ4hF7popQTRq3va4jl6u31Ut+Ji370HnBs4NeuVCC:g7yUReva4jlNoQnBXek1
Threatray 63 similar samples on MalwareBazaar
TLSH 6D64D17F32E9619CF7BBABB885B40216456A3DEAAD38D58D03011C698363374CCD5B72
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
215
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-09-22 10:50:12 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Dridex Loader
Dridex
Malware Config
C2 Extraction:
51.75.24.85:443
46.22.116.163:3074
173.249.46.113:3889
192.241.174.45:4443
Unpacked files
SH256 hash:
20d330e6dfb42f10d39f531afbf015de86a30ac2618927507d8b184d3fb3db17
MD5 hash:
236478ea881655d9aaeaadb02626411d
SHA1 hash:
6de31471599f3d44d3c3c023d4a89fa1825678a8
SH256 hash:
fad520c254c454082f4e306a38fb6cfc28cb5d5dde2bba62f17c01525f7ed8a0
MD5 hash:
b0eb6113378cac5460b3080e9ace888a
SHA1 hash:
f9997e2048f6b6379f5934e9d03e82d9d7846b24
Detections:
win_dridex_auto
SH256 hash:
31d883327033b6efb446e9416952c638152072095e6fbfab537b74bee477b6ca
MD5 hash:
ce85500cad88257b43d84cda7cc264fa
SHA1 hash:
bbfb63b922408ff7a3390da07c94885145371b40
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 31d883327033b6efb446e9416952c638152072095e6fbfab537b74bee477b6ca

(this sample)

  
Delivery method
Distributed via web download

Comments