MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e97fefe6532aa26f3e02b14d750be78b7c0774f91f7ccd1518906e7ab34b68f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9e97fefe6532aa26f3e02b14d750be78b7c0774f91f7ccd1518906e7ab34b68f
SHA3-384 hash: f02798c8af9c7d9bc636b3d10bab38bd6b003636197e2fea07f4ac987b99019c40d2583998adc08c7ff367123d4ac1ed
SHA1 hash: b9457c744b1fe2fe1cced03c9f0a9a3897849c18
MD5 hash: fce588d5820de0734bdfe0f31629345a
humanhash: spring-july-don-november
File name:3qto2mt4.dll
Download: download sample
Signature Dridex
File size:327'680 bytes
First seen:2020-04-09 15:39:18 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 5b6afdc8307f5ee96d265f967bfb7a69 (2 x Dridex)
ssdeep 6144:Y0Q6Iios6zVYZ4Hd3FmsNJ+vUgX6cViJk7ghnCcDmVBm7u0+xnB4ZTQ407u:YHsDZ4hNhwnghnCm4BmSHqB0
Threatray 96 similar samples on MalwareBazaar
TLSH 6D6402193EE6C073C82A98354B980EE22B7D6C033E764597FF90AF8D39F2555156A2F0
Reporter James_inthe_box
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-04-09 15:39:03 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
20 of 30 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::AllocateAndInitializeSid
ADVAPI32.dll::FreeSid
ADVAPI32.dll::SetEntriesInAclA
ADVAPI32.dll::InitializeSecurityDescriptor
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::GetTokenInformation
ADVAPI32.dll::SetSecurityDescriptorDacl
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::OpenProcessToken
ADVAPI32.dll::OpenThreadToken
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::WriteConsoleA
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleOutputCP
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::LookupPrivilegeValueW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegSetValueExA
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.dll::CreateServiceA
ADVAPI32.dll::OpenSCManagerA
ADVAPI32.dll::OpenServiceA
ADVAPI32.dll::QueryServiceStatus
ADVAPI32.dll::RegisterServiceCtrlHandlerA
ADVAPI32.dll::StartServiceCtrlDispatcherA

Comments