🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a835f5cc185fc0b87a513e16373210367f05ba7c189f20f9030908be6c69ebb0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA 5 File information Comments

SHA256 hash: a835f5cc185fc0b87a513e16373210367f05ba7c189f20f9030908be6c69ebb0
SHA3-384 hash: f9af1646beb480b31f3a42d5a535bdfb06e06ddad1940355c72e35ddc2f8c2abd787296e9488156835283beffddd0f3a
SHA1 hash: 669d5c56180c8d9d22012eabb157330e8f081346
MD5 hash: 84fa3d091bb36f07ca0c19428e5f99dd
humanhash: nine-cardinal-twelve-twelve
File name:Inv_225.xls
Download: download sample
Signature Dridex
File size:831'488 bytes
First seen:2021-01-14 07:07:33 UTC
Last seen:2021-01-14 08:53:29 UTC
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 6144:gk3hOdsylKlgryzc4bNhZF+E+W2knAck98SS0FlRVRbtgY8FpxVdH43KV6zTvGNC:098ZKldbOhVH43jzTQLoPR
TLSH 8505928A7785C9F6D655DA721C6EC6E02327BC48EE8A53C734947B2EBE35EB04CC1181
Reporter JAMESWT_WT
Tags:Dridex DropBox

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Application name is Microsoft Excel
Office document is in OLE format
Office document contains VBA Macros
OLE dump

MalwareBazaar was able to identify 56 sections in this file using oledump:

Section IDSection sizeSection name
1107 bytesCompObj
2244 bytesDocumentSummaryInformation
3224 bytesSummaryInformation
4683375 bytesWorkbook
597 bytes_VBA_PROJECT_CUR/A2Vm_uCHt_FgP/CompObj
6269 bytes_VBA_PROJECT_CUR/A2Vm_uCHt_FgP/VBFrame
738 bytes_VBA_PROJECT_CUR/A2Vm_uCHt_FgP/f
80 bytes_VBA_PROJECT_CUR/A2Vm_uCHt_FgP/o
997 bytes_VBA_PROJECT_CUR/AkbT_H1B4/CompObj
10291 bytes_VBA_PROJECT_CUR/AkbT_H1B4/VBFrame
1194 bytes_VBA_PROJECT_CUR/AkbT_H1B4/f
124404 bytes_VBA_PROJECT_CUR/AkbT_H1B4/o
131047 bytes_VBA_PROJECT_CUR/PROJECT
14470 bytes_VBA_PROJECT_CUR/PROJECTwm
153876 bytes_VBA_PROJECT_CUR/VBA/A2Vm_uCHt_FgP
163379 bytes_VBA_PROJECT_CUR/VBA/ALv3D_XbvF_QcGh
173938 bytes_VBA_PROJECT_CUR/VBA/AkbT_H1B4
181782 bytes_VBA_PROJECT_CUR/VBA/AqeNc_pBq_iPZl_i1bx
196207 bytes_VBA_PROJECT_CUR/VBA/NmrB4Upr
201007 bytes_VBA_PROJECT_CUR/VBA/Sheet1
212762 bytes_VBA_PROJECT_CUR/VBA/ThisWorkbook
228820 bytes_VBA_PROJECT_CUR/VBA/XD8aKwKOGDgr
233285 bytes_VBA_PROJECT_CUR/VBA/Y4pH0_8zVO_pdC
2416727 bytes_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
259704 bytes_VBA_PROJECT_CUR/VBA/__SRP_0
261009 bytes_VBA_PROJECT_CUR/VBA/__SRP_1
271398 bytes_VBA_PROJECT_CUR/VBA/__SRP_10
28156 bytes_VBA_PROJECT_CUR/VBA/__SRP_11
291740 bytes_VBA_PROJECT_CUR/VBA/__SRP_12
30180 bytes_VBA_PROJECT_CUR/VBA/__SRP_13
311725 bytes_VBA_PROJECT_CUR/VBA/__SRP_14
32240 bytes_VBA_PROJECT_CUR/VBA/__SRP_15
33961 bytes_VBA_PROJECT_CUR/VBA/__SRP_16
34166 bytes_VBA_PROJECT_CUR/VBA/__SRP_17
356545 bytes_VBA_PROJECT_CUR/VBA/__SRP_2
36540 bytes_VBA_PROJECT_CUR/VBA/__SRP_3
371422 bytes_VBA_PROJECT_CUR/VBA/__SRP_4
38156 bytes_VBA_PROJECT_CUR/VBA/__SRP_5
392343 bytes_VBA_PROJECT_CUR/VBA/__SRP_6
40170 bytes_VBA_PROJECT_CUR/VBA/__SRP_7
41528 bytes_VBA_PROJECT_CUR/VBA/__SRP_8
42156 bytes_VBA_PROJECT_CUR/VBA/__SRP_9
431576 bytes_VBA_PROJECT_CUR/VBA/__SRP_a
44156 bytes_VBA_PROJECT_CUR/VBA/__SRP_b
453300 bytes_VBA_PROJECT_CUR/VBA/__SRP_c
46156 bytes_VBA_PROJECT_CUR/VBA/__SRP_d
474481 bytes_VBA_PROJECT_CUR/VBA/__SRP_e
48270 bytes_VBA_PROJECT_CUR/VBA/__SRP_f
491410 bytes_VBA_PROJECT_CUR/VBA/dir
505986 bytes_VBA_PROJECT_CUR/VBA/e0sfU_hqn_dmQ0
512551 bytes_VBA_PROJECT_CUR/VBA/grAZJYwpE6
5217910 bytes_VBA_PROJECT_CUR/VBA/xjVQaMntiK0W
5397 bytes_VBA_PROJECT_CUR/grAZJYwpE6/CompObj
54266 bytes_VBA_PROJECT_CUR/grAZJYwpE6/VBFrame
5538 bytes_VBA_PROJECT_CUR/grAZJYwpE6/f
560 bytes_VBA_PROJECT_CUR/grAZJYwpE6/o

Intelligence


File Origin
# of uploads :
2
# of downloads :
176
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
dridex xls.7z
Verdict:
Malicious activity
Analysis date:
2021-01-14 07:14:07 UTC
Tags:
ta505 loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a window
Using the Windows Management Instrumentation requests
Creating a file in the %AppData% directory
Searching for the window
Searching for many windows
Launching a process
Creating a process with a hidden window
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Document image
Document image
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl
Score:
76 / 100
Signature
Antivirus detection for URL or domain
Creates processes via WMI
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with base64 encoded strings
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 339567 Sample: Inv_225.xls Startdate: 14/01/2021 Architecture: WINDOWS Score: 76 27 Antivirus detection for URL or domain 2->27 29 Multi AV Scanner detection for submitted file 2->29 31 Machine Learning detection for sample 2->31 33 4 other signatures 2->33 7 WMIC.exe 17 2->7         started        11 EXCEL.EXE 163 30 2->11         started        process3 dnsIp4 23 impulsionfood.com 217.160.0.179, 443, 49729 ONEANDONE-ASBrauerstrasse48DE Germany 7->23 25 192.168.2.1 unknown unknown 7->25 19 C:\Windows\Temp\gaqnm.dll, PE32 7->19 dropped 21 C:\Users\user\AppData\...\ipaO64BN[1].php, PE32 7->21 dropped 13 rundll32.exe 7->13         started        15 conhost.exe 7->15         started        file5 process6 process7 17 rundll32.exe 13->17         started       
Threat name:
Script-Macro.Trojan.Alien
Status:
Malicious
First seen:
2021-01-14 07:08:48 UTC
File Type:
Document
Extracted files:
68
AV detection:
12 of 46 (26.09%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet loader macro macro_on_action
Behaviour
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Modifies system certificate store
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks processor information in registry
Office loads VBA resources, possible macro or embedded object present
JavaScript code in executable
Loads dropped DLL
Blocklisted process makes network request
Dridex Loader
Dridex
Process spawned unexpected child process
Malware Config
C2 Extraction:
52.73.70.149:443
8.4.9.152:3786
185.246.87.202:3098
50.116.111.64:5353
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Email_stealer_bin_mem
Author:James_inthe_box
Description:Email in files like avemaria
Rule name:IPPort_combo_mem
Author:James_inthe_box
Description:IP and port combo
Rule name:Select_from_enumeration
Author:James_inthe_box
Description:IP and port combo
Rule name:SharedStrings
Author:Katie Kleemola
Description:Internal names found in LURK0/CCTV0 samples
Rule name:UAC_bypass_bin_mem
Author:James_inthe_box
Description:UAC bypass in files like avemaria

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

Excel file xls a835f5cc185fc0b87a513e16373210367f05ba7c189f20f9030908be6c69ebb0

(this sample)

  
Delivery method
Distributed via web download

Comments