🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 397789d79018695835660c20259c034c2c2ccee3cda2ca0bd62847826159eecb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 397789d79018695835660c20259c034c2c2ccee3cda2ca0bd62847826159eecb
SHA3-384 hash: 0de63caf276a1cf6a7445966d511ba0d7cf556995efe9a6a5d60dff78788fc446222571cb3b38fd005ef0f453f41739c
SHA1 hash: 512ba9a322b172b2c417d0c36756e0d90ead35b2
MD5 hash: dbaa390edbf04d9cd2263a1c0bec79a9
humanhash: oven-michigan-march-chicken
File name:dbaa390e_by_Libranalysis
Download: download sample
Signature Dridex
File size:164'864 bytes
First seen:2021-05-03 18:04:00 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash e6aa540e1f4085a198af68216e7e3577 (200 x Dridex)
ssdeep 3072:Xz63mpMBf4M8+pwhukvhU7fWaX/77/DZgTmbg+MGaFplA33VBrUXCx3:Da/jkvhSlP/7bg8aFnA3brJ
Threatray 4 similar samples on MalwareBazaar
TLSH 7EF3C0C5D687C2E0ED17F83341B06D17B839AE434325C93AAFA195DC821FADA55BF602
Reporter Libranalysis
Tags:Dridex


Avatar
Libranalysis
Uploaded as part of the sample sharing project

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.GenericML
Status:
Malicious
First seen:
2021-05-03 18:04:45 UTC
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
193.200.130.181:443
95.138.161.226:2303
167.114.113.13:4125
Unpacked files
SH256 hash:
397789d79018695835660c20259c034c2c2ccee3cda2ca0bd62847826159eecb
MD5 hash:
dbaa390edbf04d9cd2263a1c0bec79a9
SHA1 hash:
512ba9a322b172b2c417d0c36756e0d90ead35b2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments