🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8939e276f27575df1ec3ecee791e30c0a46b416ccbfeadc57ec9c94ff97be22e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 8939e276f27575df1ec3ecee791e30c0a46b416ccbfeadc57ec9c94ff97be22e
SHA3-384 hash: 22898028734a7e2f241708cf5ae16ae2aeebc2e4412494539dd6919c2d2efde758a454b6dc9e8d38926628432337a36e
SHA1 hash: 1aa5c4354efdbd50a89164c967e3ebc6b1708915
MD5 hash: bf53b67e9ce48c1e2c1d4af02428f132
humanhash: arkansas-fix-salami-magazine
File name:sjAPKtporrJZCRbeanerwopnigga.ogg
Download: download sample
Signature Dridex
File size:786'432 bytes
First seen:2021-11-24 14:39:29 UTC
Last seen:2021-11-24 16:48:52 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 8c0e65d990aa46afbbebf4269ca1b019 (3 x Dridex)
ssdeep 12288:hgUMGSOMwSG0umMqCImuoOQa0W2KUdgV+2CFDLhbUy0sp2Xf:oVehIrf
Threatray 5'462 similar samples on MalwareBazaar
TLSH T10FF48EDDB428F3DDC1A41B3312601B00594D7B9C964B28A9EEAB7CD5E2F4DDAC8D84B1
Reporter malwarelabnet
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
134
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 527944 Sample: sjAPKtporrJZCRbeanerwopnigga.ogg Startdate: 24/11/2021 Architecture: WINDOWS Score: 68 40 64.251.25.156 INFOLINK-MIA-US United States 2->40 42 185.148.168.15 EVERSCALE-ASDE Germany 2->42 44 2 other IPs or domains 2->44 48 Found malware configuration 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Yara detected Dridex unpacked file 2->52 54 C2 URLs / IPs found in malware configuration 2->54 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        13 rundll32.exe 9->13         started        15 rundll32.exe 9->15         started        17 4 other processes 9->17 process6 19 rundll32.exe 11->19         started        21 WerFault.exe 2 9 13->21         started        23 WerFault.exe 13->23         started        25 WerFault.exe 9 15->25         started        27 WerFault.exe 15->27         started        29 WerFault.exe 9 17->29         started        31 WerFault.exe 9 17->31         started        33 WerFault.exe 17->33         started        35 WerFault.exe 17->35         started        process7 37 WerFault.exe 23 9 19->37         started        dnsIp8 46 192.168.2.1 unknown unknown 37->46
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-11-24 14:40:16 UTC
File Type:
PE (Dll)
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
107.170.4.227:443
178.128.222.53:8116
185.148.168.15:4664
64.251.25.156:6602
Unpacked files
SH256 hash:
5c56281ef0fa1b811b9b0fb0f3f879d1c40395d6340e2aacf07335f6289c93a5
MD5 hash:
bf39f804371d381b05d6276d359e8c19
SHA1 hash:
6c1c1cda1a216d87e54bb631633d77b2b976c58b
Detections:
win_dridex_auto
SH256 hash:
74b4729d70fd7083c5c38be94226385533c9dc9a5ecb392a3ecbc2364781b763
MD5 hash:
d462c4de4b888938de40729219875a37
SHA1 hash:
10f2e66428287e317152ac9fdb9a92db070c3afa
Detections:
win_doppeldridex_auto
SH256 hash:
8939e276f27575df1ec3ecee791e30c0a46b416ccbfeadc57ec9c94ff97be22e
MD5 hash:
bf53b67e9ce48c1e2c1d4af02428f132
SHA1 hash:
1aa5c4354efdbd50a89164c967e3ebc6b1708915
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 8939e276f27575df1ec3ecee791e30c0a46b416ccbfeadc57ec9c94ff97be22e

(this sample)

  
Delivery method
Distributed via web download

Comments