MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d0f043627dea5de72eae3fd54dd228dcc4320e8802200dbf21bcbe1cce0bf4a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3d0f043627dea5de72eae3fd54dd228dcc4320e8802200dbf21bcbe1cce0bf4a
SHA3-384 hash: 29181e290fe61fb2deb197fcaec717ca870d1d0c3ee97d98c8f853bdffc693412c4540704ad2a5bf17cc0f51c055a692
SHA1 hash: 088274fa4220f7b19d7c25587398b545b144703d
MD5 hash: 49df3279ba75201fd07b6f3b72eda8c4
humanhash: mango-nuts-emma-bravo
File name:SecuriteInfo.com.Trojan.GenericKD.42867339.7572.29960
Download: download sample
Signature Dridex
File size:315'568 bytes
First seen:2020-03-20 09:31:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5cc71ea43c0a3a5a235d40a389b9a11b (1 x Dridex)
ssdeep 6144:NCA4NjQzhvtj28R/W7IznI+CGCtNrMRkuLYG:LzhhL/UITJCDNr9G
Threatray 640 similar samples on MalwareBazaar
TLSH 97646C0BFEA1E085F87A84FAFA4EF532543B7D694DD12081B9411928EDB960CC7B93D1
Reporter SecuriteInfoCom
Tags:Dridex

Code Signing Certificate

Organisation:YVXTOAKKHFHCALJJDJ
Issuer:YVXTOAKKHFHCALJJDJ
Algorithm:sha1WithRSA
Valid from:Mar 7 07:17:30 2020 GMT
Valid to:Dec 31 23:59:59 2039 GMT
Serial number: -5E669932EDFA3C50B1474340E34F9991
Thumbprint Algorithm:SHA256
Thumbprint: E6B754246AC6DB3DF453CBD73440381C24A36EB3D139D4CB287ADD00E12BE1CE
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Dridex
Status:
Malicious
First seen:
2020-03-19 20:02:50 UTC
File Type:
PE (Exe)
Extracted files:
22
AV detection:
28 of 30 (93.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

Executable exe 3d0f043627dea5de72eae3fd54dd228dcc4320e8802200dbf21bcbe1cce0bf4a

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::VirtualAllocEx
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
KERNEL32.dll::GetCommandLineW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::GetTempFileNameW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyA
ADVAPI32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::BroadcastSystemMessageW
USER32.dll::CreateMenu

Comments