MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7c41d3cb9da597f0b3ef1c95212493924b8b0553641af97fa4a70b9e440fb019. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7c41d3cb9da597f0b3ef1c95212493924b8b0553641af97fa4a70b9e440fb019
SHA3-384 hash: 98e283bc71f39fc4b265f319fbbaa4851f186a097645e237ebe186f8d6abe1b49bed6e455e41e9002f63cffd959f56d5
SHA1 hash: 6f6c77ca3e41f7228db04eda544aca9e3d0106d4
MD5 hash: 20700bcbc8b1134f79ba73423626f1fa
humanhash: lion-speaker-jupiter-lactose
File name:20700bcbc8b1134f79ba73423626f1fa.dll
Download: download sample
Signature Dridex
File size:556'419 bytes
First seen:2020-11-28 11:23:50 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 108c03d319577150f623cda6e1e3914f (4 x Dridex)
ssdeep 6144:7+dBKd3douH2Hnfe1DAXxlzn15BnyR1vwVYhQU7gW:6do1i21sBlDpyR19h7EW
Threatray 13 similar samples on MalwareBazaar
TLSH F1C4D590BDA91261E4AD0E32664779BB05DB3443F673712626E73FE4E4B01B43DBA321
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
260
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 324141 Sample: ocG9wRZ3BK.dll Startdate: 28/11/2020 Architecture: WINDOWS Score: 52 12 g.msn.com 2->12 16 Multi AV Scanner detection for submitted file 2->16 18 Machine Learning detection for sample 2->18 7 loaddll32.exe 1 2->7         started        signatures3 process4 process5 9 WerFault.exe 6 9 7->9         started        dnsIp6 14 192.168.2.1 unknown unknown 9->14
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2020-11-28 11:24:05 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
7c41d3cb9da597f0b3ef1c95212493924b8b0553641af97fa4a70b9e440fb019
MD5 hash:
20700bcbc8b1134f79ba73423626f1fa
SHA1 hash:
6f6c77ca3e41f7228db04eda544aca9e3d0106d4
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 7c41d3cb9da597f0b3ef1c95212493924b8b0553641af97fa4a70b9e440fb019

(this sample)

  
Delivery method
Distributed via web download

Comments