MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f44a7e56eb2efe65e35576ea02c37a740a7ec8c8d12b57be29012ad9894dad1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 6f44a7e56eb2efe65e35576ea02c37a740a7ec8c8d12b57be29012ad9894dad1
SHA3-384 hash: d681d86909329eda4712ca109a404856d789f27d10cdff5bbf7933b119d31d766477c81c84da9cb3eddcf710b3fac9a8
SHA1 hash: 6ab752300d08173085b7e24e211be8d1181e5e38
MD5 hash: 5c5bd5ebf70a0167f148513e60ade642
humanhash: romeo-foxtrot-summer-skylark
File name:5c5bd5ebf70a0167f148513e60ade642.dll
Download: download sample
Signature Dridex
File size:38'813 bytes
First seen:2020-10-16 18:02:38 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 768:L7nS4oGVxWGjj5UHwL5bQW7/CsWnAnYZ8Ttnl7lc:LrS3ixBjj5UQaW75WAY6Ttnfc
Threatray 26 similar samples on MalwareBazaar
TLSH DB036C03C9E6D6F0C4A7A0B9983BD1681B2759E7570578E607F16F1EDF23A426B30E81
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
146
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2020-10-16 18:04:10 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
6f44a7e56eb2efe65e35576ea02c37a740a7ec8c8d12b57be29012ad9894dad1
MD5 hash:
5c5bd5ebf70a0167f148513e60ade642
SHA1 hash:
6ab752300d08173085b7e24e211be8d1181e5e38
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 6f44a7e56eb2efe65e35576ea02c37a740a7ec8c8d12b57be29012ad9894dad1

(this sample)

  
Delivery method
Distributed via web download

Comments