MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 642ab82c74a436b00f64a17174e23f40a64b721b6128e80a70e3cbffc7d3424a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 642ab82c74a436b00f64a17174e23f40a64b721b6128e80a70e3cbffc7d3424a
SHA3-384 hash: fda7960af58bda7914197e39017e8558945ec62ae36fd1ceed945fc012e698801b77582b1d85231d95742e419e7162ec
SHA1 hash: 3fd3d813417c0872d1a1374439351dd53500a024
MD5 hash: 1b870dab19a3650ab790037ae327b7cb
humanhash: mirror-gee-dakota-robin
File name:1b870dab19a3650ab790037ae327b7cb.exe
Download: download sample
Signature Dridex
File size:380'416 bytes
First seen:2021-01-21 18:21:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 19aaa5da174ff18bf421cfc33a7b8e4b (1 x Dridex)
ssdeep 6144:YaYJieOxulbaInXR692g7q7D0SmQDCmC21MQ26+dI5SfcDG6I/ryHx6a8tY+f:YbJZOxuYIX8jq7wzACmCMnHxG6XRT8S
TLSH AC84AE9CA1D94640F413A679C74BABF247CED9741B26FC023EDF61E60ADE87047EA601
Reporter abuse_ch
Tags:Dridex exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
1b870dab19a3650ab790037ae327b7cb.exe
Verdict:
No threats detected
Analysis date:
2021-01-21 18:24:48 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Sending a UDP request
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file has a writeable .text section
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-01-21 18:22:05 UTC
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet loader
Behaviour
Suspicious use of WriteProcessMemory
Dridex Loader
Dridex
Malware Config
C2 Extraction:
194.225.58.214:443
211.110.44.63:5353
69.164.207.140:3388
198.57.200.100:3786
Unpacked files
SH256 hash:
642ab82c74a436b00f64a17174e23f40a64b721b6128e80a70e3cbffc7d3424a
MD5 hash:
1b870dab19a3650ab790037ae327b7cb
SHA1 hash:
3fd3d813417c0872d1a1374439351dd53500a024
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

Executable exe 642ab82c74a436b00f64a17174e23f40a64b721b6128e80a70e3cbffc7d3424a

(this sample)

Comments