MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5d2ab3a55ea082117d480a9ec3461a96f831b2107ffdf57c1385f8ab2c4f31d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 9
| SHA256 hash: | 5d2ab3a55ea082117d480a9ec3461a96f831b2107ffdf57c1385f8ab2c4f31d0 |
|---|---|
| SHA3-384 hash: | fbb1927028905a5dfea82c6e560e92073966a7d73157a7cc25ef646cf71b5f0a1f48cca5421d3635ceb634a80ca7846f |
| SHA1 hash: | 421fe163f3428a9d164172cc88543ca0e8f8d502 |
| MD5 hash: | c157d0a0deec07e42d6365a82b73af97 |
| humanhash: | aspen-oscar-hydrogen-five |
| File name: | Dridex dll |
| Download: | download sample |
| Signature | Dridex |
| File size: | 663'552 bytes |
| First seen: | 2021-11-17 15:08:45 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 6ee6d183d3880a500fe4c20e1521f405 (17 x Dridex) |
| ssdeep | 12288:PTgTeyLeMTeGPeWnyyju+JUEleC5MK5q6JeY/eeFeajgcNagjycdeajOqHeiZWim:PTgayCMaGWWyyi+eEoCGKE68YGeIaEcm |
| Threatray | 5'340 similar samples on MalwareBazaar |
| TLSH | T130E4BF94A4DAB6CFD613DB75A4F1E3878C7E184CC2304FAEC152C69990E4B95023E79B |
| Reporter | |
| Tags: | dll Dridex |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
198.199.70.22:6602
164.68.99.3:5007
142.93.218.86:4664
Unpacked files
69741e9ae94870e00669dfede5b502b3051ce3d73e688e99d2025506469b9ab4
88e28fd812e1c5056067dfa50d21ca28d66b4c419c1bb0d2af27309b9fcd682e
23dbff4b60095055eba4951fc104c9988379b1d3442c9e5bc0592a05c3a01de7
2838421699d06344ca689b1dcf11777581c15a3302eb9ef801081c340335892c
e8ee4909eebec883590b2d1ab49d1e0f4c9e6667accd687032e2d67d99c0d953
362e03f5f1194bcc16cfc14bd64662e9a715edf9458006804cc7b69e63c61941
ead4628c8fa616f6d9c54cfd4351942693ca978fc273b34917c4055b1418f538
8e1aef426727d6b526d31cf86a7d9269164a6fb3e22b1cedfbf787ce927b35c3
b2b43eefd7ae4cedb7d504f44ccdba410d0465017a92becfbc9730e57893671d
10e5f3b96a81bb3b849a9dbba33d6f297d38b417e7d6269fbcff0ce876dcb47e
4b156a5377a6c50e046dfdad0699fe26946a4e72f83fb602f95f61e50116d614
5d2ab3a55ea082117d480a9ec3461a96f831b2107ffdf57c1385f8ab2c4f31d0
c85f3aabe5c9efaa175ba9f18dc7b14a86a0aeb6206a78dbc01b9f4aef45ca1e
65c6aef17acd34ac4cda6b90182ee7d85ecdfca18532db4f5007df51519ea7ef
76772af43f50edd471246d7840b25497825b6538b78ea66d1d5928631ffdfe85
834a8705f44eec48b042c99b0ae27caffa3bec191e6269fbf0bfd6675a44f20e
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DridexLoader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 dropper C2 parsing function |
| Rule name: | DridexV4 |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 Payload |
| Rule name: | dridex_loader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex Loader |
| Rule name: | MALWARE_Win_DLLLoader |
|---|---|
| Author: | ditekSHen |
| Description: | Detects unknown DLL Loader |
| Rule name: | win_doppeldridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.doppeldridex. |
| Rule name: | win_dridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.dridex. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.