MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f6ca81f9e658fca42b50aaacf38bb2aa842ae5ef28867883a69d4790f307fb4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9f6ca81f9e658fca42b50aaacf38bb2aa842ae5ef28867883a69d4790f307fb4
SHA3-384 hash: ef539521be45a80adce9b4bf796363f75c50be0c662fad11905d56dd3428b824c484b4ed247a942c4ca177e8688ec0e1
SHA1 hash: 3bbcc1658c20cd785cdcd4c82111941f938ecba7
MD5 hash: 8092baee3c9f70fad5f98c33212d660f
humanhash: wyoming-delaware-mobile-artist
File name:mncejd.exe
Download: download sample
Signature Dridex
File size:196'608 bytes
First seen:2020-07-08 13:53:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7bef67479607a06a205cb5032f04f908 (3 x Dridex)
ssdeep 3072:9hrdAiAC7M+cmDxVjHMNPDA44aoHwIW0JSqN56RmPYQirT4jgd5wtJEO/2afKaE4:9hrCi/bVV7QPDA4xoHwI3JSqSRmPliXr
Threatray 636 similar samples on MalwareBazaar
TLSH 81141259B37CA4B6DACA387216548B3A40507D63893786677AC43E2C7F7D685F032326
Reporter JAMESWT_WT
Tags:Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
260
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-07-08 13:55:05 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

Executable exe 9f6ca81f9e658fca42b50aaacf38bb2aa842ae5ef28867883a69d4790f307fb4

(this sample)

  
Delivery method
Distributed via web download

Comments