🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6865297b72bbfe341d91e32e052debfae3bcd41d8cd883f6bf4a2d665fa00b0f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 6865297b72bbfe341d91e32e052debfae3bcd41d8cd883f6bf4a2d665fa00b0f
SHA3-384 hash: cf88f3b2d2cfa8faa0316a2c8bccdd47dc198ce592f8a418849d928d7f26cc4763616a900bf47b0e43d349ab76d7e6ca
SHA1 hash: e6afafdd6c583e32f8b6cebc286b1892fb6acb3a
MD5 hash: 18363d169ce47cbbbc620ac11362f078
humanhash: helium-leopard-quiet-finch
File name:SecuriteInfo.com.Variant.Fragtor.44159.18448.17087
Download: download sample
Signature Dridex
File size:786'432 bytes
First seen:2021-11-24 16:48:57 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 3408863a87d01409eccbe58d6d3e764c (3 x Dridex)
ssdeep 6144:jmHk0ZwiaiIiu4KiU0OiaiOw8i4isCAiKeoiyj3o10Yxc7Ijse4WjPPMOnnnEi1m:lQRDlh/tRVPT1rTjybATge4W70Onn1m
Threatray 5'465 similar samples on MalwareBazaar
TLSH T13AF47C67440FD860F6C58A3977BC6885ED85E2628F123FBAB9422C2563352BCD5B3317
Reporter SecuriteInfoCom
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 528047 Sample: SecuriteInfo.com.Variant.Fr... Startdate: 24/11/2021 Architecture: WINDOWS Score: 68 40 64.251.25.156 INFOLINK-MIA-US United States 2->40 42 185.148.168.15 EVERSCALE-ASDE Germany 2->42 44 2 other IPs or domains 2->44 48 Found malware configuration 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Yara detected Dridex unpacked file 2->52 54 C2 URLs / IPs found in malware configuration 2->54 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        13 rundll32.exe 9->13         started        15 rundll32.exe 9->15         started        17 4 other processes 9->17 process6 19 rundll32.exe 11->19         started        21 WerFault.exe 2 9 13->21         started        23 WerFault.exe 13->23         started        25 WerFault.exe 9 15->25         started        27 WerFault.exe 15->27         started        29 WerFault.exe 9 17->29         started        31 WerFault.exe 9 17->31         started        33 WerFault.exe 17->33         started        35 3 other processes 17->35 process7 37 WerFault.exe 23 9 19->37         started        dnsIp8 46 192.168.2.1 unknown unknown 37->46
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-24 15:18:38 UTC
File Type:
PE (Dll)
AV detection:
21 of 28 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22202 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
107.170.4.227:443
178.128.222.53:8116
185.148.168.15:4664
64.251.25.156:6602
Unpacked files
SH256 hash:
862e216f75aa7c64c3faf89f9c37a8695694692dd51b4504ecac9fa780fca327
MD5 hash:
bebd20f9b54c6822dca68e6136aae228
SHA1 hash:
4135b3b31a394cf3453c8afb5e8bf4916a44f2ae
Detections:
win_doppeldridex_auto
SH256 hash:
0e7d0c189e4b802906e698d5a1e52c43ca429e8c306bd8abe93175548e0c90a5
MD5 hash:
6ed566b5b06b9b89c4ffbc7aeac172d0
SHA1 hash:
ad265667f3aea6d029f1bbc7f14abeabfd6c5f1b
Detections:
win_dridex_auto
SH256 hash:
6865297b72bbfe341d91e32e052debfae3bcd41d8cd883f6bf4a2d665fa00b0f
MD5 hash:
18363d169ce47cbbbc620ac11362f078
SHA1 hash:
e6afafdd6c583e32f8b6cebc286b1892fb6acb3a
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 6865297b72bbfe341d91e32e052debfae3bcd41d8cd883f6bf4a2d665fa00b0f

(this sample)

  
Delivery method
Distributed via web download

Comments