🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2fc2cf518643cee722a0ceb7cac0b01d827f0433b6e917cf563a796d381e5ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a2fc2cf518643cee722a0ceb7cac0b01d827f0433b6e917cf563a796d381e5ae
SHA3-384 hash: ebecd9f4fe173533d03dd111de795af333fe21a0b927971cfa4ee304dfbc2a8a5fcfbfcdebe1d66b612652b8abce0578
SHA1 hash: b651e8ff800909a72c60b03484c1feaa28eac1b7
MD5 hash: 36e7d65586ea7f7083eb415213470514
humanhash: cold-ink-white-sad
File name:36e7d655_by_Libranalysis
Download: download sample
Signature Dridex
File size:164'864 bytes
First seen:2021-05-03 18:04:34 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash e6aa540e1f4085a198af68216e7e3577 (200 x Dridex)
ssdeep 3072:kC63mpMBf4M8+pwhukvhU7fWaX/77/DZgTmbg+MGaFplA33VBrU8Cx3:7a/jkvhSlP/7bg8aFnA3bra
TLSH 30F3C0C5D687C2E0ED17F83341B06D17B839AE434325C93AAFA195DC821FADA55BF602
Reporter Libranalysis
Tags:Dridex


Avatar
Libranalysis
Uploaded as part of the sample sharing project

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2021-05-03 18:05:28 UTC
AV detection:
11 of 47 (23.40%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
193.200.130.181:443
95.138.161.226:2303
167.114.113.13:4125
Unpacked files
SH256 hash:
a2fc2cf518643cee722a0ceb7cac0b01d827f0433b6e917cf563a796d381e5ae
MD5 hash:
36e7d65586ea7f7083eb415213470514
SHA1 hash:
b651e8ff800909a72c60b03484c1feaa28eac1b7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments