MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e0f7672152a1ea6ab3224965a614846b55040ffb7442fc1e3c12391d82c2cf0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6e0f7672152a1ea6ab3224965a614846b55040ffb7442fc1e3c12391d82c2cf0
SHA3-384 hash: 91e3ea550d678190f93a45a7a45671052d14f641b2d8d37ddbbe99c471c4cad0de11460a790b9bb34784522b97f0cbdd
SHA1 hash: a41e5353e885cab9299c36b409fdbaa139d5d326
MD5 hash: cf54b2f542ae944cc31f5e6f9b34903e
humanhash: twelve-california-five-red
File name:cf54b2f542ae944cc31f5e6f9b34903e.dll
Download: download sample
Signature Dridex
File size:606'208 bytes
First seen:2021-02-02 08:46:17 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 02745f1a10e80302727ab47402bc3150 (1 x Dridex)
ssdeep 12288:AwTvsKRUCzh6I9DIPmeA7Xnmzztu8mQxrswbhdXJi:ACsH9eeAznOEIs6hb
TLSH 6BD4D1F8B94084B5CC81007CE43DE6A8D9AD7DA78E11E11372FB7F5F7A39982C615A09
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
127
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 347235 Sample: 7e3XMcwAEm.dll Startdate: 02/02/2021 Architecture: WINDOWS Score: 48 10 Multi AV Scanner detection for submitted file 2->10 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 6 9 6->8         started       
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
6e0f7672152a1ea6ab3224965a614846b55040ffb7442fc1e3c12391d82c2cf0
MD5 hash:
cf54b2f542ae944cc31f5e6f9b34903e
SHA1 hash:
a41e5353e885cab9299c36b409fdbaa139d5d326
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 6e0f7672152a1ea6ab3224965a614846b55040ffb7442fc1e3c12391d82c2cf0

(this sample)

  
Delivery method
Distributed via web download

Comments