🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0cf81ece9fd2e03542e987bc746c9807757bab25157d71fec93753e996170b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a0cf81ece9fd2e03542e987bc746c9807757bab25157d71fec93753e996170b6
SHA3-384 hash: 4924e6946408872d9c342a8f590a4645a7dbdfad22bcb18230306b11f578f2b234c7cc4101a6b9380ec6bad4693aa7f3
SHA1 hash: 0f87361ac663a08ca5a055b038d29a86318cb199
MD5 hash: 3d97224feee277457ab33aecceeeed7a
humanhash: eight-fruit-undress-artist
File name:3d97224f_by_Libranalysis
Download: download sample
Signature Dridex
File size:164'864 bytes
First seen:2021-05-03 19:02:53 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash e6aa540e1f4085a198af68216e7e3577 (200 x Dridex)
ssdeep 3072:ad63mpMBf4M8+pwhukvhU7fWaX/77/DZgTmbg+MGaFplA33VBrU1Cx3:ua/jkvhSlP/7bg8aFnA3brX
Threatray 66 similar samples on MalwareBazaar
TLSH D6F3C0C5D687C2E0ED17F83341B06D17B835AE434325C93AAFA195DC821FADA55BF602
Reporter Libranalysis
Tags:Dridex


Avatar
Libranalysis
Uploaded as part of the sample sharing project

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.GenericML
Status:
Malicious
First seen:
2021-05-03 19:03:25 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
193.200.130.181:443
95.138.161.226:2303
167.114.113.13:4125
Unpacked files
SH256 hash:
a0cf81ece9fd2e03542e987bc746c9807757bab25157d71fec93753e996170b6
MD5 hash:
3d97224feee277457ab33aecceeeed7a
SHA1 hash:
0f87361ac663a08ca5a055b038d29a86318cb199
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments