🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4eea330f8fdd2a503795c9b25346b3e752ba18b7ef2c776fff5b21bdc8a8e12e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 4eea330f8fdd2a503795c9b25346b3e752ba18b7ef2c776fff5b21bdc8a8e12e
SHA3-384 hash: 077601b7907998a63be3cdeaf72edbdce941980086f099b4d353be4d6cfc6745b303d002f441953185c6cc929a2a22ce
SHA1 hash: f0f3b496ae64e5115fd39a00dff04b351c84f941
MD5 hash: 5f788c0a85f200cc321cd0593a18ffa0
humanhash: pizza-neptune-nineteen-nebraska
File name:Holiday Survey Fraud 996188331.xlsb
Download: download sample
Signature Dridex
File size:108'123 bytes
First seen:2021-11-29 14:38:01 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 3072:b/b95ZIJSjq0gQ+5dZZCDZpyYl+fw5snd3Wgd+PH:vd4SjNgJ5dZEZLod+v
TLSH T122B302AD662AD025C54F5C3E905B7DEAF221C41194C0EA71B279307C8E23A37175E5EE
Reporter JAMESWT_WT
Tags:Dridex xlsb xlsx

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Holiday Survey Fraud 996188331.xlsb
Verdict:
Malicious activity
Analysis date:
2021-11-29 14:40:17 UTC
Tags:
macros40

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Creating a window
Сreating synchronization primitives
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Excel4Macro
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mshta stripped
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Document-Excel.Infostealer.Dridex
Status:
Malicious
First seen:
2021-11-29 14:38:10 UTC
File Type:
Document
Extracted files:
20
AV detection:
19 of 27 (70.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro xlm
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments