MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 994f20ffe53c72f3831982fdf62f5404459306f2afb42a495db19920d5e579e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 994f20ffe53c72f3831982fdf62f5404459306f2afb42a495db19920d5e579e8
SHA3-384 hash: 50b7e8c66dba3d446e4bb351e22aaee4fcfcff66c1d3aaf490e7ed1f4e0c71b10d6b401d1dbd892913f40ca998c168d6
SHA1 hash: 880cfc60b8343a6f6fce1c605d5685b6042f7ac6
MD5 hash: ba75745e46d7cc9b6af78de4788d5617
humanhash: fruit-juliet-harry-white
File name:Претензия.xll
Download: download sample
Signature Dridex
File size:654'848 bytes
First seen:2021-12-01 08:43:57 UTC
Last seen:2021-12-01 11:13:22 UTC
File type:Excel file xll
MIME type:application/x-dosexec
imphash be710ba34b048ab0098050ccf62e369c (18 x Formbook, 14 x Dridex, 9 x AgentTesla)
ssdeep 12288:F0Ws7IMtR4yVld8bzbBSreZhgFK/UqWN:F0bdkX1vcL
Threatray 6 similar samples on MalwareBazaar
TLSH T190D46D55BECA6EA1EF7F47BB8361D62D0226735E03A1A6CF760305993951FC2443EA03
Reporter pr0xylife
Tags:Dridex xll

Intelligence


File Origin
# of uploads :
3
# of downloads :
159
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Претензия.xll
Verdict:
No threats detected
Analysis date:
2021-12-01 08:39:23 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-vm greyware packed packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Tnega
Status:
Malicious
First seen:
2021-12-01 07:58:13 UTC
File Type:
PE (Dll)
Extracted files:
2
AV detection:
18 of 28 (64.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments