🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73aee1f4ca4cb7ff2b9ec1425a875d2a556e7fcc05a8d406019ea3177ae8b2d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments

SHA256 hash: 73aee1f4ca4cb7ff2b9ec1425a875d2a556e7fcc05a8d406019ea3177ae8b2d3
SHA3-384 hash: 4451e1bb6e583e461cbc655ad672be4c6a61f8ee6262c104d791dcd32347c84a84997b0bb004e2a16026c6244ddb09bd
SHA1 hash: bc0ae16f27e40a518bc560f52f15e9480041f1b2
MD5 hash: f1c07da60c9f4de564e9b33158e3c12d
humanhash: apart-nineteen-winter-table
File name:SecuriteInfo.com.W32.AIDetect.malware1.17868.21805
Download: download sample
Signature Dridex
File size:479'232 bytes
First seen:2021-12-20 23:18:09 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash d67883ee85eede67419711a8fbd7ca0d (43 x Dridex)
ssdeep 6144:o0610FnNqVnt0Rt1CVlp0R5aMSw8EekUXnAwd37izAQqK/o2B6LjiReYiL1EU:j6MSw8EekuB37izvjI/yU
TLSH T103A4AF3181C5528AD705123423DA8065227F5326CC957FBF9CF982732A6BAEDDE3E0D6
Reporter SecuriteInfoCom
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
321
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 543164 Sample: SecuriteInfo.com.W32.AIDete... Startdate: 21/12/2021 Architecture: WINDOWS Score: 72 17 120.50.40.185 M1NET-SG-APM1NETLTDSG Singapore 2->17 19 139.162.113.169 LINODE-APLinodeLLCUS Netherlands 2->19 21 2 other IPs or domains 2->21 23 Found malware configuration 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Yara detected Dridex unpacked file 2->27 29 2 other signatures 2->29 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        process6 13 rundll32.exe 11->13         started        process7 15 WerFault.exe 23 9 13->15         started       
Threat name:
Win32.Worm.Cridex
Status:
Malicious
First seen:
2021-12-20 19:26:23 UTC
File Type:
PE (Dll)
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
doppeldridex dridex
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22206 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
120.50.40.185:443
139.59.14.223:8172
121.40.104.209:6602
139.162.113.169:593
Unpacked files
SH256 hash:
45feffe2ffb4ccc9be7a9f83dff63872fd2cf0f2e73294437e129049c311e6e7
MD5 hash:
aa101a4ee8059becbb1578b06d55d1e6
SHA1 hash:
d6a347f70407b7afcc5575cb211b24e46ab614a5
Detections:
win_dridex_auto
Parent samples :
cfdd42a62ed1a612d0a08b55668512b1bb8e48e4540ec123f2bfc72ca0df0728
49b240bca4cd10a3fa1537f926fdaca286a42dadf8b1b97c4f7da5fb19f0edc2
21b2d88c08031360ac8030f7a8a147f203a44d1ace183dd17975eda2a093c4ff
f5bae6a4fc581989e33d29352755daff2de067a3bdefd91d6b18a452466269d3
208b0e4bc7dafb4ba814c3f7bf734c4e7fa4e930d80bd56870981392a94ce380
ab3bf17d94030cb3a6df9c01c2f2473dfe7c3a3e2d73e5c2f28c13569bdb6e3f
78e1c5e1e6bb037e2dede98a0248aa43317b5d101639d54073882fe980768e8c
f0680e26115bcd02184db5dea1c8b6134608ac211e6ea37d0ec12137eda29941
73aee1f4ca4cb7ff2b9ec1425a875d2a556e7fcc05a8d406019ea3177ae8b2d3
1b58475744840f7ace6661cbcaacd05e0c4dfaa1958ad9d057b35a79497b01e4
13ea7c503533713d9dd7351bdab7d52ee2e5347d27c2cf8f74c889c4c5430185
3dc02a6cf72c63b8a2308cd39d45eebc64580c74bd14027bcfb306752db0596d
f33baf46bb93789e96536d92df5fe70f8ede45c9cecd6e4ef7f24b0c3f032053
7f2c7437aff6d900e5bdf9f51880113b6c6f8677c1be8a9fbb1f23eadb7d602c
4d3fd93b2369a670084abd4e9623896a6b836ebd5e843bc00a00c3179eb68976
d970cedd941e247e1b7aa55c150feb091ae7ef67b2b7ec353b87c657a16697c9
61e1955b6f145e66d59fa0d927165135c9b49738c7557212d09687c5d6666e84
4533b582eb2b0c0664312bb69409f6cbd3f4400005c3d5722ca9e02f7eb68e6d
44f4ef22f6a6edb59396c97a9a553c1e76850f3cbeb38a9746ed4df5741cb770
bfddf1832640408e64d941058b3030aafd9f945bb5c821641ca833fba4401590
c237ec97aa1aa067b567fa4bf87c6d102ccd35b51a23ea5100ed3559bed9ee07
36d55638947ea8b31a80bca274a6ec720b665dfd4cbb511e19b241c9666da0ca
dd5173abdb268c5833e6d1945dc61f87fd9aa807e3b610f547b47fc802f9f2b1
377576fdb5ae91a0f4f0835c81babb80b68910ba17ef224ae4fa108d9153c7d4
b8e72a9dfabd57a4b11dbdba14b8e96ca9b081091d5268d08a6c0e999e38a95a
9da7c4d51a2d18aa3e79bfe0c2fa6fb1a6e1754c73985bce90c4c5c1a90e41d3
58810e4b465473493c929a18f2eb596aa0d721ad62d23a157f2c0a6916fd0aa2
685cfa389b847b15c5b4d0af55eb9e4e9944db38c630789c307e808118eda8aa
cb9173ee1d6bd874578ec9fb4cfc61fee233dd1721d4ae8b38d71c5c23e7ff78
649b719b3ee467ea1a1c824cfc5db7a1eae33b05b9182ee4190541d32bf96b8d
599cdcdb3891f9d46b8b320943f8112a8eec63b732272d82ce8e95a1fbc3c6e6
7cc0d16fe4e01e60f5eed66d1d6e58a9143129e8326cb16f8126664ce821f2d1
1cb0d92d0a1bd0226fe5c1aa7d841d188924c4dc5b57d3397111733d24f1d0e4
bdf841f003aa7aa8a2a842918b18c9797508af4e8bb72ebe8343073df16172a7
c7a28cc9d0d632be29b01873282dd07879a961b63ef923cee43ff16b752b38d2
bc38064e8938cff283b33b23ae76faa2dc1a08d5866981c7324183b5922d7434
c5b52cd1ada1c319e8e3dab79eb0373853b052075685a793fd3471179a3af564
4d62e3327b3a0440069f61c89524c4af3af7a9aec9c0664465c6c1f4650fe77b
529a5bd3d20b261adf861d16181308f6ba1c78954a06ac81c03a14ca91b927dd
87e2dad373f75f5c0a200821523aebe45f6f4103b51fb0155ed2bf060ec50b04
88902dbfead91e58e427308d0a4ab5c936b1c54d31d926ae99cd1642cd6a4bbc
8179bc64652d44d11b75f64430faa3bf9ebb6a4086af14ee4018b8bf36e685a3
c5b456ade77af6125a2c002c0c41f7d757e970250e4a9e472b1fa8489f26869b
SH256 hash:
73aee1f4ca4cb7ff2b9ec1425a875d2a556e7fcc05a8d406019ea3177ae8b2d3
MD5 hash:
f1c07da60c9f4de564e9b33158e3c12d
SHA1 hash:
bc0ae16f27e40a518bc560f52f15e9480041f1b2
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:dridex_loader
Author:kevoreilly
Description:Dridex Loader
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:win_doppeldridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppeldridex.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 73aee1f4ca4cb7ff2b9ec1425a875d2a556e7fcc05a8d406019ea3177ae8b2d3

(this sample)

  
Delivery method
Distributed via web download

Comments