MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a4b602ad5624c7570395c8d61fb558727f2e37ce763377d0ddeb93b176b592fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 10
| SHA256 hash: | a4b602ad5624c7570395c8d61fb558727f2e37ce763377d0ddeb93b176b592fb |
|---|---|
| SHA3-384 hash: | 9f5f1a4229a7af3af0f00f5731e1b156b5e5d299596970c1c052c6ac5fc656daf88887be4520fc9274735861584faf4f |
| SHA1 hash: | 6f40daf3effebd4a63d90f1fe7a21bf7a3b5be43 |
| MD5 hash: | c153fbaae1a7947942c074e1d8c59b34 |
| humanhash: | hotel-arizona-florida-sad |
| File name: | SecuriteInfo.com.W32.Dridex.GB.genEldorado.6285.28277 |
| Download: | download sample |
| Signature | Dridex |
| File size: | 520'192 bytes |
| First seen: | 2021-12-20 23:18:40 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 2b1b4edc6ebe7eca63696f6220126258 (7 x Dridex) |
| ssdeep | 6144:M5a3RjZ1XrZvR7Z9JrZdR5ZbR1Z9RVZ1RvZpR17fRrZpRrTZRfZ3Rr3fRJZfRlZn:RbTFRJXfZrFTfVBokoa7fGs8E7l |
| Threatray | 5'730 similar samples on MalwareBazaar |
| TLSH | T12BB48E29E83826A4FC351F3875E0B3CEB653D9145B3B81707B7D9B348782991ECA61C6 |
| Reporter | |
| Tags: | dll Dridex |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
188.214.241.242:4664
93.104.209.107:8116
5.189.190.214:593
Unpacked files
9a92587563a7be70787c52f46a5bbd5240cf012ba5ec77e23d04bda3d652a9c7
145b6b65c2627e10b663d7f1609ff56380262d9dc8850b7ac31cb3ee4feb511d
94a784a5377541aa2f994182ff9308cc1265938088aa87a2a1d3198f29509793
a4b602ad5624c7570395c8d61fb558727f2e37ce763377d0ddeb93b176b592fb
673ff75f1fc774b6bf83689e9394b17587c795611b3ef2dae9c865bf6949d344
2b25238c00aa0596c7132d869b2a208803a51c22b76e9b22562f930be4d1a17b
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DridexLoader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 dropper C2 parsing function |
| Rule name: | DridexV4 |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex v4 Payload |
| Rule name: | dridex_loader |
|---|---|
| Author: | kevoreilly |
| Description: | Dridex Loader |
| Rule name: | MALWARE_Win_DLLLoader |
|---|---|
| Author: | ditekSHen |
| Description: | Detects unknown DLL Loader |
| Rule name: | win_doppeldridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.doppeldridex. |
| Rule name: | win_dridex_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.dridex. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.