MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73542918c46a8a028d9a19169f5cb4fa09f3ea609085e3efd5324d07254d7280. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 73542918c46a8a028d9a19169f5cb4fa09f3ea609085e3efd5324d07254d7280
SHA3-384 hash: 4f2d3e858fcdf9391d1774e2e5d0d068c309a803809454dcf15ee4994b35ec02acc5bd496dcc684b640f727b9d029932
SHA1 hash: 28c36d73c060fb2840ea9f457b8d6f5c88c304ab
MD5 hash: 0b421211722f02d8274abac42e7c4fd9
humanhash: december-muppet-jersey-earth
File name:67091463.vbs
Download: download sample
Signature Dridex
File size:5'000'288 bytes
First seen:2020-07-24 22:43:41 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 3072:U4j9/TOfnYJKrM0E75wKzLecJ/46TeKXuXMTofduA:NjlTsa5wK/zTBuX
TLSH 0736E0A0EDF46991E27EC6B305F590B6837B3A26D6117C72095F19440E15AF84EF383E
Reporter malware_traffic
Tags:Dridex vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
338
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Sending an HTTP GET request
Creating a file in the %temp% directory
Threat name:
Script-VBS.Backdoor.Quakbot
Status:
Malicious
First seen:
2020-07-24 22:45:07 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of WriteProcessMemory
Executes dropped EXE
Blacklisted process makes network request
Blacklisted process makes network request
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments