🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64fc64d39aa5da0b7b45ba083f17c4db5045e9f144ba24c2f54634a87213df92. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 64fc64d39aa5da0b7b45ba083f17c4db5045e9f144ba24c2f54634a87213df92
SHA3-384 hash: fd54a2fd3959b15f632f80d32300a73fe08b89dac2df9d1a94da7ad5beea6d45f2cdbca165a1444fecc099707eb78818
SHA1 hash: 9cee48d9cbbfcc6bd6d2e4f75da0dd617d9dd5a6
MD5 hash: ec73ef419b4594329ccbfc485a9b0906
humanhash: september-robin-beryllium-alaska
File name:ec73ef419b4594329ccbfc485a9b0906.dll
Download: download sample
Signature Dridex
File size:188'416 bytes
First seen:2021-08-11 16:14:25 UTC
Last seen:2021-08-11 17:07:00 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash c88b1b8168f2947a82592f1323fdc522 (3 x Dridex)
ssdeep 3072:c1JzSxp5PpRh7phfrv/6jC5KHWnzD7xC3/o1WXDCFUBUL1iMhmDEwmuFWwqF:c1JGz5pX7fz+C5kUzDA36bFUc1i7EwR2
Threatray 4'860 similar samples on MalwareBazaar
TLSH T1DB04E090E7CB1269E6631875152D332264A27F219670EE9ECE1DC62887774236F3E3C7
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
383
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Dridex Dropper
Detection:
malicious
Classification:
troj.evad.bank
Score:
84 / 100
Signature
C2 URLs / IPs found in malware configuration
Dridex dropper found
Found malware configuration
Found PHP interpreter
Machine Learning detection for sample
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to detect sandboxes / dynamic malware analysis system (file name check)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 463564 Sample: 8ak3Utgmpa.dll Startdate: 11/08/2021 Architecture: WINDOWS Score: 84 41 87.98.128.76 OVHFR France 2->41 43 80.241.218.90 CONTABODE Germany 2->43 45 103.161.172.109 AARNET-AS-APAustralianAcademicandResearchNetworkAARNe unknown 2->45 49 Found malware configuration 2->49 51 Dridex dropper found 2->51 53 Yara detected Dridex unpacked file 2->53 55 3 other signatures 2->55 9 loaddll32.exe 1 2->9         started        signatures3 process4 signatures5 57 Tries to detect sandboxes / dynamic malware analysis system (file name check) 9->57 12 rundll32.exe 9->12         started        15 rundll32.exe 9->15         started        17 rundll32.exe 9->17         started        19 4 other processes 9->19 process6 signatures7 59 Tries to detect sandboxes / dynamic malware analysis system (file name check) 12->59 61 Tries to delay execution (extensive OutputDebugStringW loop) 12->61 21 WerFault.exe 9 15->21         started        24 WerFault.exe 15->24         started        26 WerFault.exe 9 17->26         started        28 WerFault.exe 17->28         started        30 rundll32.exe 19->30         started        33 WerFault.exe 2 9 19->33         started        35 WerFault.exe 11 19->35         started        37 WerFault.exe 19->37         started        process8 dnsIp9 47 192.168.2.1 unknown unknown 21->47 63 Tries to detect sandboxes / dynamic malware analysis system (file name check) 30->63 39 WerFault.exe 23 9 30->39         started        signatures10 process11
Threat name:
Win32.Worm.Cridex
Status:
Malicious
First seen:
2021-08-11 16:15:11 UTC
AV detection:
15 of 27 (55.56%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
80.241.218.90:443
103.161.172.109:13786
87.98.128.76:5723
Unpacked files
SH256 hash:
cf3a070c354c281aead5882e1abba391d0c0044f6a453e11b3f845b5cf8f4988
MD5 hash:
45c90e07c15935db64bbbdd5e28589c5
SHA1 hash:
0f0ee12b2537d2ac14c73b2e9e0a6ae1bfdaa3fc
Detections:
win_dridex_auto
SH256 hash:
c68b834f34c731f8e44f5378354bab9ae4721c6a5a3f191350e9f58ac1ff8a00
MD5 hash:
3babb6aac54ab6e95d7bf4c476ea2d9f
SHA1 hash:
c930a5091b903e1cec4075a3bd18fbc27c8cb14a
Detections:
win_doppeldridex_auto
SH256 hash:
64fc64d39aa5da0b7b45ba083f17c4db5045e9f144ba24c2f54634a87213df92
MD5 hash:
ec73ef419b4594329ccbfc485a9b0906
SHA1 hash:
9cee48d9cbbfcc6bd6d2e4f75da0dd617d9dd5a6
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 64fc64d39aa5da0b7b45ba083f17c4db5045e9f144ba24c2f54634a87213df92

(this sample)

  
Delivery method
Distributed via web download

Comments