MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5cb8c6baf6d41a0dd663d092ebb31ef7bdaa4370fb0f8cb6fd35b6a8744f31c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 9
| SHA256 hash: | 5cb8c6baf6d41a0dd663d092ebb31ef7bdaa4370fb0f8cb6fd35b6a8744f31c9 |
|---|---|
| SHA3-384 hash: | 401a8584dfaa3ab13a1e5064ed1a47a08a8b28e8383257df73f86ce0fc7d920aac0ee7219d9d8ce08f06b01eec88590b |
| SHA1 hash: | edebdd979430258f89db7bf02d9a2b653ed0f8f7 |
| MD5 hash: | f3a6bac3b47e4dba8c9a05905e519a0a |
| humanhash: | pasta-fish-vegan-beryllium |
| File name: | SecuriteInfo.com.W32.AIDetect.malware2.21196.25721 |
| Download: | download sample |
| Signature | Dridex |
| File size: | 438'272 bytes |
| First seen: | 2021-11-22 20:57:46 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 8dec1a105645cd34f7153c99220eeea4 (17 x Dridex) |
| ssdeep | 6144:iqaMQWTCJkdk5k7kBM7A9kkr+pt4PlaMEQ/j8I0r6BHAE754k:i8maeqIGs+N4kMEyg6uEFp |
| Threatray | 5'444 similar samples on MalwareBazaar |
| TLSH | T13B949F80F32B83E4DE09DE3B04FC985C153856E8FF5B16D5739C81FC35E49A898A6629 |
| Reporter | |
| Tags: | dll Dridex |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
86.107.98.232:8333
188.165.214.166:4664
144.91.110.219:9217
Unpacked files
2dd54462c65a469a2611be091d84fa71a4c1b5b61d020f4058296153941d9e13
ee1259ba7e41be5e8f11fb7ed2fb983bd9a48e757cf59690336aa63ac2497dba
92a5ea2c1f1cc5177f54568b6d6b878f46a2bd3e49daf93f6385d304dcc1ee40
ba5fb468274de91023a4b8d14ff5b79a5531fed3cc818cdc93969b5fdb1a309d
b169abddcc96b1c9b61cd112734ad9e1d13af76ac9eb33b12c00fec870ed322d
2db0e926b1d6d60ab8138c008be5cad1ee2dda7a2cbbd27496953a97464b7511
8cb564d0a6548b35d96707b24a90ec361d82098f25381257fb8300ee5d27c6dc
106cd82325eacb5a9eedef1a7e54a9ad4e982469abe0b54583fbd4b8a0bd35f2
553cce1f64c0364094da5b64103f5bf184559eb9a4f7ebc5e14897b89ab6eda1
887f1d15b4c5a13871220261516df2fdb3410ed7a8b6088deee0d38610cbe68a
5aab487dfb1bd8c811dcc0fa8c9c9e762bb8df69424fd585d60a4bba53664599
ddcaa1c7ba38d83e0f34da7cce150905cd0246f15334b9feadd8dcab5cd991ee
b1029b6074fcc508c36bfd3c9c1ec582da3650faae2a9af1eb867ad3e05fc513
5cb8c6baf6d41a0dd663d092ebb31ef7bdaa4370fb0f8cb6fd35b6a8744f31c9
be193b9e9d20df4110f8da469af38bb99f445a173b13d1941da6be8d8c81d1fd
5092d010953226e366db6d47af4bf9886179ea6eb2655f3e70d4a1a82af1c7d5
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DridexLoader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 dropper C2 parsing function |
| Rule name: | DridexV4 |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 Payload |
| Rule name: | dridex_loader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex Loader |
| Rule name: | MALWARE_Win_DLLLoader |
|---|---|
| Author: | ditekSHen |
| Description: | Detects unknown DLL Loader |
| Rule name: | win_doppeldridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.doppeldridex. |
| Rule name: | win_dridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.dridex. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.