MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a07f03acb1bd6c83e7b79bbd2c28b672f533cc58b194a97b0c1f6002e54b4313. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a07f03acb1bd6c83e7b79bbd2c28b672f533cc58b194a97b0c1f6002e54b4313
SHA3-384 hash: 31a83975f8b97b516a56212edafe1fd5db1605fa4a5492439bd082257f06cd650303781f65609040e01e5e9742fda08c
SHA1 hash: 44b82ea1bdbaf3c1c384816f2ab20e7c41a9792b
MD5 hash: 0bb62d39a7241b58bfbcb200cb534ff7
humanhash: moon-queen-orange-mobile
File name:0bb62d39a7241b58bfbcb200cb534ff7.dll
Download: download sample
Signature Dridex
File size:884'546 bytes
First seen:2020-11-09 19:25:08 UTC
Last seen:2020-11-15 22:40:21 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 24576:0c+0xXN0G9JQ3W8bjn7i0RrCmKOJy72vf7SZ+m4IP:ya9Re7/m0gmn3vWZ+m4IP
Threatray 2 similar samples on MalwareBazaar
TLSH 821512213D43D436D2621874CE6DCABACB5CBF110B6491CB33E64D272E3E4E15A3E65A
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
4
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
a
c
d
e
f
g
h
i
L
M
n
o
p
r
s
t
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-10 01:44:43 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll a07f03acb1bd6c83e7b79bbd2c28b672f533cc58b194a97b0c1f6002e54b4313

(this sample)

  
Delivery method
Distributed via web download

Comments