🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52d877ecef168dbb456884a1fb4d0e00bd703d473dcf8d3f296448103788c215. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 52d877ecef168dbb456884a1fb4d0e00bd703d473dcf8d3f296448103788c215
SHA3-384 hash: 87c92df13c98f890e989f4f78319479f24aa2e06323c560e619f6f8e0c9635a7865d9ea23c508bb5493755fd252ac04d
SHA1 hash: cd7b7c6ee5e636d8809966b9b06fb439bc626a9e
MD5 hash: 3524315bb90e3e4c8cede2cdd476455f
humanhash: thirteen-pizza-winter-louisiana
File name:SecuriteInfo.com.W32.AIDetect.malware1.16073.14037
Download: download sample
Signature Dridex
File size:786'432 bytes
First seen:2021-11-30 00:40:56 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 735df7fc35361ede8f9cf4d257872cbb (3 x Dridex)
ssdeep 12288:e+GSWcQaC4+WG4I4+u+AYiu6GEC+uS4au0qO+qkCSqCu+8s+e8enExinN6ZzqZPq:e+GSWcQaC4+WG4I4+u+AYiu6GEC+uS4W
Threatray 5'480 similar samples on MalwareBazaar
TLSH T19EF48DC5EA6CC3F4E1046B75A544820B57508929D3F35B8DBCFF02A68E8DEA54C87673
Reporter SecuriteInfoCom
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 530838 Sample: SecuriteInfo.com.W32.AIDete... Startdate: 30/11/2021 Architecture: WINDOWS Score: 68 36 23.253.208.162 RACKSPACEUS United States 2->36 38 51.68.138.110 OVHFR France 2->38 40 2 other IPs or domains 2->40 44 Found malware configuration 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected Dridex unpacked file 2->48 50 C2 URLs / IPs found in malware configuration 2->50 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        13 rundll32.exe 9->13         started        15 cmd.exe 1 9->15         started        17 4 other processes 9->17 process6 19 WerFault.exe 2 9 11->19         started        21 WerFault.exe 11->21         started        23 WerFault.exe 9 13->23         started        26 rundll32.exe 15->26         started        28 WerFault.exe 9 17->28         started        30 WerFault.exe 9 17->30         started        32 WerFault.exe 17->32         started        dnsIp7 42 192.168.2.1 unknown unknown 23->42 34 WerFault.exe 23 9 26->34         started        process8
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-29 22:46:32 UTC
File Type:
PE (Dll)
AV detection:
22 of 44 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22204 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
51.68.138.110:443
206.189.150.190:8116
103.109.247.10:10443
23.253.208.162:9217
Unpacked files
SH256 hash:
70f667e08af00f68025d4bc399349b183f5db854b17c99b412f49e19cfba2313
MD5 hash:
b769ccc540468a9018f2d4126784112f
SHA1 hash:
7a445a069b4161c0185ce9857cdb1e7ed3c7a36c
Detections:
win_doppeldridex_auto
SH256 hash:
df25fbf5871c11654e9752832d8c3b283518206e733c1556ffcc4f9944d56c91
MD5 hash:
bdaafb4a6aeadb9f520946a88dca4149
SHA1 hash:
9f84c78f5165757864d0c0c4f190e9a45de90b71
Detections:
win_dridex_auto
SH256 hash:
52d877ecef168dbb456884a1fb4d0e00bd703d473dcf8d3f296448103788c215
MD5 hash:
3524315bb90e3e4c8cede2cdd476455f
SHA1 hash:
cd7b7c6ee5e636d8809966b9b06fb439bc626a9e
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 52d877ecef168dbb456884a1fb4d0e00bd703d473dcf8d3f296448103788c215

(this sample)

  
Delivery method
Distributed via web download

Comments