🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a3abf81a46e3e318450f496e08d8cd0c9952f43deb4c481e19f9cfd36e884f2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments 1

SHA256 hash: a3abf81a46e3e318450f496e08d8cd0c9952f43deb4c481e19f9cfd36e884f2a
SHA3-384 hash: 57fb032b77c8ea1dbbb405aad083005cf83648435ab7296a1b893f797ee26115532511802f3dfcace1a85da46232f8bc
SHA1 hash: d9fb4101a76039316a5047da32ac29b575ef8167
MD5 hash: 11817679b95e547beb067f8e82f43108
humanhash: purple-london-whiskey-magazine
File name:11817679b95e547beb067f8e82f43108
Download: download sample
Signature Dridex
File size:663'552 bytes
First seen:2021-11-17 19:05:02 UTC
Last seen:2021-11-18 05:54:41 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash fe16443ce39f2fcea9c5accdb27a9eac (21 x Dridex)
ssdeep 12288:WUTlJzJzJBJZn/JH3lJxJLJZJdPgA1VKBUA1rlldOJw:WUJtpDv/lVbdT3IA1wBUA1rlldOK
Threatray 5'345 similar samples on MalwareBazaar
TLSH T1B2E48E0250D512FCFA898ABF155A67C1C6B310824ED1CB9E25CD07EADF64A03EE6D1B7
Reporter zbetcheckin
Tags:32 dll Dridex exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
124
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 523943 Sample: ufL7a84E0E Startdate: 17/11/2021 Architecture: WINDOWS Score: 72 17 54.37.70.105 OVHFR France 2->17 19 142.93.218.86 DIGITALOCEAN-ASNUS United States 2->19 21 2 other IPs or domains 2->21 23 Found malware configuration 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Yara detected Dridex unpacked file 2->27 29 2 other signatures 2->29 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        process6 13 rundll32.exe 11->13         started        process7 15 WerFault.exe 23 9 13->15         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-17 19:05:07 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22203 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
54.37.70.105:443
198.199.70.22:6602
164.68.99.3:5007
142.93.218.86:4664
Unpacked files
SH256 hash:
366ce87e743656480bed6528ed3e94ae78b26736c5ba547a50ed0b478a22c96c
MD5 hash:
623e9d461f59d4b47792019ca1ce52e2
SHA1 hash:
52cb160ca691b50e309969598bbd876636a615b1
Detections:
win_doppeldridex_auto
SH256 hash:
2e4da7dbe3d43e07cf011302db7302f7b8d632d6823966ee620ae30cf34662e7
MD5 hash:
fffeb707e430160c6d8914689e04389b
SHA1 hash:
5537b9332c0efbfae10f9b433bb851959bd11cc7
Detections:
win_dridex_auto
SH256 hash:
a3abf81a46e3e318450f496e08d8cd0c9952f43deb4c481e19f9cfd36e884f2a
MD5 hash:
11817679b95e547beb067f8e82f43108
SHA1 hash:
d9fb4101a76039316a5047da32ac29b575ef8167
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll a3abf81a46e3e318450f496e08d8cd0c9952f43deb4c481e19f9cfd36e884f2a

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-11-17 19:05:04 UTC

url : hxxps://49lorg.am.files.1drv.com/y4mJADHIlEWwXpRuhX_AOV58UcKKw0IrJg8q-VBvZFuuteC_q8G7mLxhop7ZXpjfkUbhI_ty_kNvmsM9dwfrGuKOck5HBDGRtS_KtUxzr1-oHnmcZt0UQ8BniPBk6OwsBoyv_iuxuL_lYx08RG2_t_n1ks0nrtTPK9xRBubyYAKgBm99nFsHQQg4azGfmK0Vqe3k6Vlzn-PUpJgjNiGCtESSw/dqrkteouzeq.mp4