MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6548eeb76a2c4321d3a7ac27b3a6bbfb663f3d38c3968d2add19a3a7ab1f75ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6548eeb76a2c4321d3a7ac27b3a6bbfb663f3d38c3968d2add19a3a7ab1f75ff
SHA3-384 hash: 3d88ce1765a2de8364be77437fd01f6b9bd58d7f4e7a5e07bcaa695e22946bcd3354f1dde98b8e2547b924f90d881696
SHA1 hash: 91879a6bdd9638a201e4400cd71d40769d7624df
MD5 hash: 50bab884a5464770220da44a00fe7a79
humanhash: friend-oxygen-pennsylvania-zebra
File name:50bab884a5464770220da44a00fe7a79.dll
Download: download sample
Signature Dridex
File size:32'460 bytes
First seen:2021-02-11 08:02:06 UTC
Last seen:2021-02-11 10:08:57 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 384:zIdaFp3K039X6m2dUoiT2VLUn5418Ss08PjYxk4h7NHRJC0NWNumK/8N+X:zIkAdA51bjY1zRjrz0N0
TLSH 8AE26C71FA5DD662C428073B8DA7D7AD52353CEE87228CEB72F40D5B7635181BA23142
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
4 / 100
Behaviour
Behavior Graph:
n/a
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
6548eeb76a2c4321d3a7ac27b3a6bbfb663f3d38c3968d2add19a3a7ab1f75ff
MD5 hash:
50bab884a5464770220da44a00fe7a79
SHA1 hash:
91879a6bdd9638a201e4400cd71d40769d7624df
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 6548eeb76a2c4321d3a7ac27b3a6bbfb663f3d38c3968d2add19a3a7ab1f75ff

(this sample)

  
Delivery method
Distributed via web download

Comments