MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6232728af29302ef0a4675b3c5a255b5e9ee800c221823ecb4d4cab8cc0f7edb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 6232728af29302ef0a4675b3c5a255b5e9ee800c221823ecb4d4cab8cc0f7edb
SHA3-384 hash: ba48b7b6b3fdb6c14630c300a2dffe0b391932be06cdd95a4cdabc358e7da3c08774f203ae067a1e94a3279f1c809f76
SHA1 hash: a16e4767112e43f150a255cad6c56d440d945380
MD5 hash: a5513cadb437d6243dc463d836a03e62
humanhash: ceiling-august-low-lactose
File name:a5513cadb437d6243dc463d836a03e62.exe
Download: download sample
Signature Dridex
File size:911'360 bytes
First seen:2021-09-21 09:46:11 UTC
Last seen:2021-09-21 11:23:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 65b7d80ef614b878121194bff58cf2d9 (1 x Dridex)
ssdeep 6144:ZXK6cyPiWCgknQ/HuyIzuTVzsMM56519p+6yTx3NJsQOe3MnjWRza5GZa:JM+ZdkmHubeaCo6CspCMC5aAa
Threatray 850 similar samples on MalwareBazaar
TLSH T11615E0036BEC5DADD8AAF63115EF4E21557EAC229950D43EA6C83CCF3DFD6A20502352
File icon (PE):PE icon
dhash icon e8864b69692b96e8 (2 x Dridex)
Reporter abuse_ch
Tags:Dridex exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
233
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
a5513cadb437d6243dc463d836a03e62.exe
Verdict:
Malicious activity
Analysis date:
2021-09-21 09:57:36 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
Detection:
malicious
Classification:
bank.troj.evad
Score:
96 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected Dridex e-Banking trojan
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Phonzy
Status:
Malicious
First seen:
2021-09-18 23:53:14 UTC
AV detection:
13 of 28 (46.43%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:10111 botnet discovery evasion trojan
Behaviour
Checks installed software on the system
Checks whether UAC is enabled
Dridex
Malware Config
C2 Extraction:
188.252.100.181:9676
42.112.35.46:8443
103.58.102.177:7443
Unpacked files
SH256 hash:
dc6316f72d6e80c41979bd3a24d817866afa2a98e5f5c95cae95c70c3d40759a
MD5 hash:
c65b3f4eb276d8fc429538a2aae21d94
SHA1 hash:
73477e65031f056aa4d164d844a8295b130d9ebe
SH256 hash:
6232728af29302ef0a4675b3c5a255b5e9ee800c221823ecb4d4cab8cc0f7edb
MD5 hash:
a5513cadb437d6243dc463d836a03e62
SHA1 hash:
a16e4767112e43f150a255cad6c56d440d945380
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:win_dridex_loader_v2
Author:Johannes Bader @viql
Description:detects some Dridex loaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments