MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 763b5323953c0899bffe4ca733732874a2b2aa64b1a4aff4714b10bbc5f28f22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 763b5323953c0899bffe4ca733732874a2b2aa64b1a4aff4714b10bbc5f28f22
SHA3-384 hash: 64718be8506afcb51241981c4c6db08fd80a82afa01c46756fce8d534607303eddc3c61c1399dfa3c89cf2ecf48d79fb
SHA1 hash: a45435a2a0a53458ce0f32d470c4677c1afbc88d
MD5 hash: 87ee46ad05bc4d64ba678864ad66c8d8
humanhash: angel-queen-mockingbird-asparagus
File name:87ee46ad05bc4d64ba678864ad66c8d8.dll
Download: download sample
Signature Dridex
File size:11'616 bytes
First seen:2022-03-01 17:40:11 UTC
Last seen:2022-03-01 19:55:26 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 192:hlgbouC58IUIFmlwxUUJzFmS8IxBr/pN5J9uTjpDpy3QyMVQlT/HXQhAq:h+9G8xIFmlgxmS8qBr/P5J9uTjBMFXhm
TLSH T115324505EB4951A6D7D041B944EBCB4EDADE0249036C3ED3E31668FB28119D3BD7EA0D
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
1'032
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 580965 Sample: 6UPWgZchJS.dll Startdate: 01/03/2022 Architecture: WINDOWS Score: 23 35 store-images.s-microsoft.com 2->35 37 Sigma detected: Suspicious Call by Ordinal 2->37 15 loaddll32.exe 1 2->15         started        signatures3 process4 process5 17 cmd.exe 1 15->17         started        process6 19 rundll32.exe 17->19         started        process7 21 rundll32.exe 19->21         started        process8 23 rundll32.exe 21->23         started        process9 25 rundll32.exe 23->25         started        process10 27 rundll32.exe 25->27         started        process11 29 rundll32.exe 27->29         started        process12 31 rundll32.exe 29->31         started        process13 33 rundll32.exe 31->33         started       
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
763b5323953c0899bffe4ca733732874a2b2aa64b1a4aff4714b10bbc5f28f22
MD5 hash:
87ee46ad05bc4d64ba678864ad66c8d8
SHA1 hash:
a45435a2a0a53458ce0f32d470c4677c1afbc88d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 763b5323953c0899bffe4ca733732874a2b2aa64b1a4aff4714b10bbc5f28f22

(this sample)

  
Delivery method
Distributed via web download

Comments