MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6067b4d4febf1c025385eab5f40934d1ffe00e3ce2d6f5bb8f6481689d48ae72. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6067b4d4febf1c025385eab5f40934d1ffe00e3ce2d6f5bb8f6481689d48ae72
SHA3-384 hash: 9242f3023a3ee1d3935449cb5a642f61ed75650fd77ed3162e8817b573c671f18402b38b4abc6067be3dc0e8bf3ec71d
SHA1 hash: 9b12ee881b75e3fe557b2e6bcc7c5e23e64110e4
MD5 hash: ef4af6cbca06f48ab1300310b6792ef1
humanhash: east-monkey-grey-asparagus
File name:SecuriteInfo.com.BehavesLike.Win32.Emotet.dc.573
Download: download sample
Signature Dridex
File size:212'992 bytes
First seen:2020-03-19 20:52:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 536db36e60853eb79f610e8e98ddc7b8 (1 x Dridex)
ssdeep 3072:psSmSTPJfFjxIoMnvMYG79a8RuvHH55ahEzlHHKMaEiss2i6I7FRYVxfmS3iTb:psSPP5F9CMYO8XZ5ahEzlnfAXveVFmI
Threatray 250 similar samples on MalwareBazaar
TLSH 07241244925B0579F9B31070429A537729003918C95DFAB2EE9CFE87F5EAA324D3B327
Reporter SecuriteInfoCom
Tags:Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

Executable exe 6067b4d4febf1c025385eab5f40934d1ffe00e3ce2d6f5bb8f6481689d48ae72

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::BuildExplicitAccessWithNameW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::AssignProcessToJobObject
WIN_SCARD_APISupports Windows Smart CardWinSCard.dll::SCardForgetCardTypeW

Comments