🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98feb009d7fbb35d7c8d19c2dc8d5cc3f69e7df9f569fae09516a171c514bc65. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments

SHA256 hash: 98feb009d7fbb35d7c8d19c2dc8d5cc3f69e7df9f569fae09516a171c514bc65
SHA3-384 hash: e0ea00118256de362cfdbdb3bf2c2bc1d8170a76c5214daeb61e3a05054ef9280bbbda7068e3d342efdaed4868cc2117
SHA1 hash: be0d34b71d1918f5b19261d72f668f1fe1a1ddcb
MD5 hash: 89cadc666b7b69fcafc6a8cc5b86ee44
humanhash: butter-two-jig-hawaii
File name:SecuriteInfo.com.ML.PE-A+Mal.EncPk-APX.14113.30942
Download: download sample
Signature Dridex
File size:438'272 bytes
First seen:2021-11-22 20:57:24 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 6e10c8576fec9d1d6e1bb3b6a941ae33 (34 x Dridex)
ssdeep 6144:ZdAvTLKLgLoLULwLTX2nWtU0xMvhVNYLT9ouiOPbL:ZdkTuEUI8unWt1MNYXNPb
Threatray 5'444 similar samples on MalwareBazaar
TLSH T1CC94BE1648DBC0A7EB845F7131857D083FB13DA2E0F98BC11D9A80AD557DA0E664CEBB
Reporter SecuriteInfoCom
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Tries to delay execution (extensive OutputDebugStringW loop)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 526716 Sample: SecuriteInfo.com.ML.PE-A+Ma... Startdate: 22/11/2021 Architecture: WINDOWS Score: 72 39 188.165.214.166 OVHFR France 2->39 41 67.207.95.35 DIGITALOCEAN-ASNUS United States 2->41 43 2 other IPs or domains 2->43 47 Found malware configuration 2->47 49 Multi AV Scanner detection for submitted file 2->49 51 Yara detected Dridex unpacked file 2->51 53 C2 URLs / IPs found in malware configuration 2->53 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        14 cmd.exe 1 9->14         started        16 rundll32.exe 9->16         started        18 4 other processes 9->18 signatures6 55 Tries to delay execution (extensive OutputDebugStringW loop) 11->55 20 WerFault.exe 9 11->20         started        22 rundll32.exe 14->22         started        24 WerFault.exe 9 16->24         started        26 WerFault.exe 16->26         started        28 WerFault.exe 9 18->28         started        30 WerFault.exe 9 18->30         started        32 WerFault.exe 18->32         started        34 2 other processes 18->34 process7 process8 36 WerFault.exe 20 9 22->36         started        dnsIp9 45 192.168.2.1 unknown unknown 36->45
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-22 20:58:15 UTC
File Type:
PE (Dll)
AV detection:
34 of 45 (75.56%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22204 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
67.207.95.35:443
86.107.98.232:8333
188.165.214.166:4664
144.91.110.219:9217
Unpacked files
SH256 hash:
3b8f4d134657d7a4af311a343d1a7e62ce4eea247a76a84fd25d52e11f5e3cbd
MD5 hash:
634e604ed91bcf8f06724c1c0c5d4641
SHA1 hash:
e0e3e2f319cbb0e3e5a09b72665acd99db3604ff
Detections:
win_dridex_auto
Parent samples :
56e14f97c8c81205095b3f88b42d3c2945b7ededde63aee819e6efd72a327a90
dbf00529c336392e707f31e7b40949e9a76f212414b73a427aef7d36e532f2ad
3e1533cd12189940ffbdacd2bc541bf165fe08b5577c0c21e426a5825bf2a070
bd5f765b253c9295e049fabc3926b1035b8637854262808a290641c6bedbf929
04123389c92b859698f919e21f1a60da8e17c1bcb0611e8ac1cea3aa33292b34
0ed4009a564ca19a5cc032d717dc08e2d29249f4a7f24bdbd59e86d18d47bfea
99bcc4e3b513807646ea3ecb2a0204ec2b7d3011918afb0ee774c13259db5158
e44e106cb30acbbb31e5d981d80343801a61312f69ebb5007d2d5196d8aadde7
64bb39b55eb68a952ef2f16d789945aa44c25a8a5c8afbb145edaa3250bac408
1947b5e89de24aac07c3986cdda6740a93c1368b7341674a68997477bd164951
b5fc1b486be903e51a7bc663d9ff8b6518845f9a81c2d88a5a6866ac409d1cb6
2994b41427aaa895a104b2b0ba0262f6ff6d88061d274245fba72d0f420ac1d7
2254b5adbaba9e592460f8cd48c9e7f4fc2df708055a3681070eb7d144b63fbf
cc8601f9a6f1311469c7013bd38c0df0656451102c9ad0d972375f47348fdcec
15a442124da8d48768fc0dac469dd05054bb7603355cdbe8aedaa64a5bc4306a
2d0ac5a3d01e467edcb6ea8c3582ae2a68522956a87c757fc30f9c3690c4362e
baaef4fef9919d88492547c701bb15c3498d93c5fe32497c7e85a540f6ebe58b
f6827c377e0b6ebc5048178608878b0630da76b5f5c1940873f9ea9a5297312f
7f833030419bce6598e6ffc80cace489d3c87de69bf0ebb89f8d5839b28fddb3
7aceed81f9a4ac530ae9fd3acc253efdd46d696640d97ca33e0de46f5c317b13
a8f577e396e42d8c6d2a15f0fac58c57e128b1b1bfb18d68f432fd06eee5d22c
9758f9a929aec5dfdc689bb73aa3a7c5a08b6d836848fe57420cd2368d9ec0ad
1eabe34f7a79c496b1d89472585778a2660edab82f7476095cb35b743e80d994
dda500d087d82aee20d1a9585a8421357ae6d0066410fdb7089b5c5bd5cb7b39
e6d4cd8b8f456f74058904d7bba9518ad498b4d643c036a6a7c16044b48b9faf
33af3eac7111f63fac5e6a6c6427af09c2f769b1f2793b8d6dcceb7d7b3eccde
35b5f47f40af69b7b325332a49377671fdf1d190204e6d4bd350cd177b83fee8
f3431287f896baf794b38302c293ec3bcbc959739a3bb462aef2c468d259d1e8
319024b7533d5eb909183507d86f012e3cbbfaf0eab9c4ad7e92d48afa7d3237
0996942e39f5bd64b86396a0f6ac66eab0acca1fda63a8895eecb08d041ea0ea
98feb009d7fbb35d7c8d19c2dc8d5cc3f69e7df9f569fae09516a171c514bc65
fa931924577eb864ee21c3e379276a2db8a527d38b87276b3d26b9d834a3d279
864a98007cf3880dc94492ac20927cfa540a25dedb322ccd9394968303ffa178
e6aeccd5f35f65a8043091481c0e3a4390520531a07e2c73a84f5ffd8f58c359
SH256 hash:
98feb009d7fbb35d7c8d19c2dc8d5cc3f69e7df9f569fae09516a171c514bc65
MD5 hash:
89cadc666b7b69fcafc6a8cc5b86ee44
SHA1 hash:
be0d34b71d1918f5b19261d72f668f1fe1a1ddcb
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:dridex_loader
Author:kevoreilly
Description:Dridex Loader
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:win_doppeldridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppeldridex.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll 98feb009d7fbb35d7c8d19c2dc8d5cc3f69e7df9f569fae09516a171c514bc65

(this sample)

  
Delivery method
Distributed via web download

Comments