MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35382c36cef5048bd57a081c6a8477048ca0ae327c81d7e18947f3ce10fb2877. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 35382c36cef5048bd57a081c6a8477048ca0ae327c81d7e18947f3ce10fb2877
SHA3-384 hash: 5be91382ceddcac52e21f69b16f9c206be897f384f20884315391d0725eef7bc622aa9301ef595f2908a57933d706ea3
SHA1 hash: 37263ba153c0506815b17daada4e891c3be68f6b
MD5 hash: 5a27dd08bcce0297128d3ea9e3faea7a
humanhash: oklahoma-chicken-lithium-five
File name:5a27dd08bcce0297128d3ea9e3faea7a.dll
Download: download sample
Signature Dridex
File size:1'016'496 bytes
First seen:2020-11-09 19:25:22 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 24576:IjOXGq89BRVHd6njFrxNbesrP8AeXkyd/R:dXT812njFrxNasrP8rXx
Threatray 2 similar samples on MalwareBazaar
TLSH 99251250B6839479D27358348968CDB6CB28BF510F786CC772C55C2B1E3A0D1AB36E7A
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
a
c
d
e
f
g
h
i
L
M
n
o
p
r
s
t
Behaviour
Behavior Graph:
Threat name:
Win32.PUA.Wacapew
Status:
Malicious
First seen:
2020-11-10 06:37:09 UTC
AV detection:
10 of 29 (34.48%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 35382c36cef5048bd57a081c6a8477048ca0ae327c81d7e18947f3ce10fb2877

(this sample)

  
Delivery method
Distributed via web download

Comments