MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9108a662aaa71b838b70214bc2d933729b78cfcc096032b8a667560a53527270. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9108a662aaa71b838b70214bc2d933729b78cfcc096032b8a667560a53527270
SHA3-384 hash: 6b2beca56e87afd10e8a5bd7f9e1eb341b7d6b98f805cc4ca2f8183132f4e96c981bfc9e289ab9026e410efdcc2c9be6
SHA1 hash: ae348c22f44fbe524621d5ff23188e46110e892e
MD5 hash: f44a0bd5d0606373995263f82e7d87d5
humanhash: six-snake-alaska-north
File name:f44a0bd5d0606373995263f82e7d87d5.dll
Download: download sample
Signature Dridex
File size:1'554'852 bytes
First seen:2020-11-18 10:54:45 UTC
Last seen:2020-11-18 13:20:44 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 24576:DXxU1Db0+xzg2oI8r/5QBd+XodsMPt0EqZDA4MSEcA:LcDYWg2oI8r/6d+DMPu96SG
Threatray 4 similar samples on MalwareBazaar
TLSH 8C75F1227792D079C1278139CED9E8FD8665BD16DF2418C730C87F6F3A369114B3AA1A
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
148
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-11-18 10:55:05 UTC
File Type:
PE (Dll)
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
9108a662aaa71b838b70214bc2d933729b78cfcc096032b8a667560a53527270
MD5 hash:
f44a0bd5d0606373995263f82e7d87d5
SHA1 hash:
ae348c22f44fbe524621d5ff23188e46110e892e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 9108a662aaa71b838b70214bc2d933729b78cfcc096032b8a667560a53527270

(this sample)

  
Delivery method
Distributed via web download

Comments