🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4dc9b2f11546e5bf8fb9901809a0707ff1e23acdc52742b991ddff18ce03733c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Maldoc score: 23


Intelligence 9 IOCs YARA 5 File information Comments

SHA256 hash: 4dc9b2f11546e5bf8fb9901809a0707ff1e23acdc52742b991ddff18ce03733c
SHA3-384 hash: cdc8549d4009f9afb86f18adfca95af7d504b06bab536c8ea1e19cbecaa6f95668e060ed84ad34fc6dc01e6aec3c8602
SHA1 hash: f7743ba186492f6cb788837ec510a79999ef951c
MD5 hash: b876d6897e25db661b02a79c2e68eb0d
humanhash: solar-blue-yellow-cold
File name:SecuriteInfo.com.Trojan.GenericKD.45953106.28492.6364
Download: download sample
Signature Dridex
File size:184'490 bytes
First seen:2022-07-13 08:06:45 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 3072:BfX1i6uPN1bVcrA7ZHLygMa6HNKb3VzH2nIZ3IfTVR90YTH9tIaZ5UbjlUbV055E:BfX1i6e3bVCQhLvMBHNKLVWwm2m9tIoh
TLSH T11504120EE86AB54FC4968436148C0DDD3BB0688D9510FFC7114A2F3A9D565C7BF8B297
TrID 42.2% (.XLAM) Excel Macro-enabled Open XML add-in (83500/1/13)
29.1% (.XLSM) Excel Microsoft Office Open XML Format document (with Macro) (57500/1/12)
17.2% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
8.8% (.ZIP) Open Packaging Conventions container (17500/1/4)
2.0% (.ZIP) ZIP compressed archive (4000/1)
Reporter SecuriteInfoCom
Tags:Dridex xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 23
OLE dump

MalwareBazaar was able to identify 42 sections in this file using oledump:

Section IDSection sizeSection name
A197 bytesEyGhjx_VnzYGAULd_rychbrqWFV/CompObj
A2283 bytesEyGhjx_VnzYGAULd_rychbrqWFV/VBFrame
A338 bytesEyGhjx_VnzYGAULd_rychbrqWFV/f
A40 bytesEyGhjx_VnzYGAULd_rychbrqWFV/o
A597 bytesFkgs_WthepD_kh_Si_AtinenmqE_PU/CompObj
A6286 bytesFkgs_WthepD_kh_Si_AtinenmqE_PU/VBFrame
A738 bytesFkgs_WthepD_kh_Si_AtinenmqE_PU/f
A80 bytesFkgs_WthepD_kh_Si_AtinenmqE_PU/o
A997 bytesLiRpBHOwmUrrjAmH/CompObj
A10298 bytesLiRpBHOwmUrrjAmH/VBFrame
A11106 bytesLiRpBHOwmUrrjAmH/f
A1217860 bytesLiRpBHOwmUrrjAmH/o
A131051 bytesPROJECT
A14464 bytesPROJECTwm
A153450 bytesVBA/EyGhjx_VnzYGAULd_rychbrqWFV
A163706 bytesVBA/Fkgs_WthepD_kh_Si_AtinenmqE_PU
A172589 bytesVBA/J_NV_wWU
A181998 bytesVBA/LiRpBHOwmUrrjAmH
A19991 bytesVBA/Sheet1
A201547 bytesVBA/ThisWorkbook
A216864 bytesVBA/_VBA_PROJECT
A222482 bytesVBA/__SRP_0
A23178 bytesVBA/__SRP_1
A24214 bytesVBA/__SRP_2
A25206 bytesVBA/__SRP_3
A261368 bytesVBA/dir
A271752 bytesVBA/hLYnl_VEzm
A283140 bytesVBA/maxlXCEcw_qE
A292651 bytesVBA/rE__YPVUnvXtolwXBknCzaPN
A3097 byteshLYnl_VEzm/CompObj
A31266 byteshLYnl_VEzm/VBFrame
A3238 byteshLYnl_VEzm/f
A330 byteshLYnl_VEzm/o
A3497 bytesmaxlXCEcw_qE/CompObj
A35268 bytesmaxlXCEcw_qE/VBFrame
A3638 bytesmaxlXCEcw_qE/f
A370 bytesmaxlXCEcw_qE/o
A3897 bytesrE__YPVUnvXtolwXBknCzaPN/CompObj
A39280 bytesrE__YPVUnvXtolwXBknCzaPN/VBFrame
A4038 bytesrE__YPVUnvXtolwXBknCzaPN/f
A410 bytesrE__YPVUnvXtolwXBknCzaPN/o
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecWorkbook_OpenRuns when the Excel Workbook is opened
SuspiciousOpenMay open a file
SuspiciousPutMay write to a file (if combined with Open)
SuspiciousBinaryMay read or write a binary file (if combined with Open)
SuspiciousCreateMay execute file or a system command through WMI
SuspiciousShowWindowMay hide the application
SuspiciousGetObjectMay get an OLE object with a running instance
SuspiciousChrMay attempt to obfuscate specific strings (use option --deobf to deobfuscate)
SuspiciousChrWMay attempt to obfuscate specific strings (use option --deobf to deobfuscate)
SuspiciousXorMay attempt to obfuscate specific strings (use option --deobf to deobfuscate)
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
537
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Using the Windows Management Instrumentation requests
Launching a process
Creating a process with a hidden window
Launching the default Windows debugger (dwwin.exe)
DNS request
Result
Verdict:
Malicious
File Type:
Excel File with Macro
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm cmd macros macros-on-open rundll32
Label:
Malicious
Suspicious Score:
9.9/10
Score Malicious:
1%
Score Benign:
0%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
92 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates processes via WMI
Document contains an embedded VBA macro which may execute processes
Document contains an embedded VBA with base64 encoded strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Behaviour
Behavior Graph:
Threat name:
Script-Macro.Trojan.IcedID
Status:
Malicious
First seen:
2021-03-23 05:21:32 UTC
File Type:
Document
Extracted files:
69
AV detection:
19 of 27 (70.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
macro
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Modifies system certificate store
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Office loads VBA resources, possible macro or embedded object present
Blocklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_TrickBot_xlsm_20210324
Author:abuse.ch
Description:Detects TrickBot xlsm
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments