🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85dd0bbdc1dde143ffd3906d04ce15fa415b0f66abfaeb1f3476007c5664438e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments 1

SHA256 hash: 85dd0bbdc1dde143ffd3906d04ce15fa415b0f66abfaeb1f3476007c5664438e
SHA3-384 hash: 013f7f7f48e0bce987166a3f4b58dbcae878900ca4ff887ba9442d35055c40165ff436f4e1030acdfe4dd43e35c3335a
SHA1 hash: d5f6aa91491a9188942acbabcc84ee8a19716c1f
MD5 hash: a0f8bce825cba9c9b9d23b8688333fd7
humanhash: friend-white-summer-september
File name:a0f8bce825cba9c9b9d23b8688333fd7
Download: download sample
Signature Dridex
File size:663'552 bytes
First seen:2021-11-17 19:09:30 UTC
Last seen:2021-11-17 21:11:02 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash fe16443ce39f2fcea9c5accdb27a9eac (21 x Dridex)
ssdeep 12288:/DTlJzJzJBJZn/JH3lJxJLJZJdPgA1VKBUA1rlldyJw:/DJtpDv/lVbdT3IA1wBUA1rlldyK
Threatray 5'346 similar samples on MalwareBazaar
TLSH T12CE48E0250D512FCFA898ABF155A67C1C6B310824ED1CB9E25CD07EADF64A03EE6D1B7
Reporter zbetcheckin
Tags:32 dll Dridex exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
129
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
67%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 523947 Sample: amYc2YMb76 Startdate: 17/11/2021 Architecture: WINDOWS Score: 72 18 54.37.70.105 OVHFR France 2->18 20 142.93.218.86 DIGITALOCEAN-ASNUS United States 2->20 22 2 other IPs or domains 2->22 26 Found malware configuration 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected Dridex unpacked file 2->30 32 2 other signatures 2->32 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        process6 13 rundll32.exe 11->13         started        process7 15 WerFault.exe 23 9 13->15         started        dnsIp8 24 192.168.2.1 unknown unknown 15->24
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-17 19:10:06 UTC
AV detection:
21 of 45 (46.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22203 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
54.37.70.105:443
198.199.70.22:6602
164.68.99.3:5007
142.93.218.86:4664
Unpacked files
SH256 hash:
2e4da7dbe3d43e07cf011302db7302f7b8d632d6823966ee620ae30cf34662e7
MD5 hash:
fffeb707e430160c6d8914689e04389b
SHA1 hash:
5537b9332c0efbfae10f9b433bb851959bd11cc7
Detections:
win_dridex_auto
SH256 hash:
f1ed52ad87b26e0c211f46fcd725d86105c38f958770820f0ee328540551adef
MD5 hash:
b6e05912e6e76d6c6965d89370557be6
SHA1 hash:
319900317d20bcb9cda18c596abe1795d9a470f9
Detections:
win_doppeldridex_auto
SH256 hash:
85dd0bbdc1dde143ffd3906d04ce15fa415b0f66abfaeb1f3476007c5664438e
MD5 hash:
a0f8bce825cba9c9b9d23b8688333fd7
SHA1 hash:
d5f6aa91491a9188942acbabcc84ee8a19716c1f
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 85dd0bbdc1dde143ffd3906d04ce15fa415b0f66abfaeb1f3476007c5664438e

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-11-17 19:09:32 UTC

url : hxxps://api.onedrive.com/v1.0/shares/u!aHR0cHM6Ly9vbmVkcml2ZS5saXZlLmNvbS9lbWJlZD9yZXNpZD04RUM3QzYyQTdDMkY5OThGJTIxMTA1JmF1dGhrZXk9IUFCVUJ2dXdBRnNDOVlPTQ/root/content/