MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 77734c9865fd31b3551462126dc27387775ba3a969ec1cb4b6c9fccf45ce43dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 77734c9865fd31b3551462126dc27387775ba3a969ec1cb4b6c9fccf45ce43dd
SHA3-384 hash: 16a40f02f96ac8de9bdaf6c578885b4cc1e482c887d05d1e8c2e53e37b614c6d138020659f7bc88d46067f2dd681d800
SHA1 hash: 126f8b501b94fd623e5d79001af70a0e9eb78033
MD5 hash: 88b8438400a22f5a648e75a6a53d51be
humanhash: skylark-jig-asparagus-happy
File name:88b8438400a22f5a648e75a6a53d51be.dll
Download: download sample
Signature Dridex
File size:710'726 bytes
First seen:2021-01-29 08:32:28 UTC
Last seen:2021-01-29 10:54:49 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 12288:ASts0Ljpezsf/Lrxn9AiQwvM8hZDgh6cVBsepVEsY7/ICmco0ADXET:HtrszsHxfjv7Dg1Dc7/IxET
Threatray 8 similar samples on MalwareBazaar
TLSH 61E4E161BDD0E479E76E22304C16DCBA026ABC0416BEFC6F32DE2D5F15B2262F116794
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
150
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 345873 Sample: kelll7HJO9.dll Startdate: 29/01/2021 Architecture: WINDOWS Score: 48 13 Multi AV Scanner detection for submitted file 2->13 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 7 9 6->8         started        dnsIp5 11 192.168.2.1 unknown unknown 8->11
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-01-27 08:50:29 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
77734c9865fd31b3551462126dc27387775ba3a969ec1cb4b6c9fccf45ce43dd
MD5 hash:
88b8438400a22f5a648e75a6a53d51be
SHA1 hash:
126f8b501b94fd623e5d79001af70a0e9eb78033
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 77734c9865fd31b3551462126dc27387775ba3a969ec1cb4b6c9fccf45ce43dd

(this sample)

  
Delivery method
Distributed via web download

Comments