MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8b125a1162491b5a6d0a4372aea196007ba8f96ea4dfcda4c05ad5a65d03378. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a8b125a1162491b5a6d0a4372aea196007ba8f96ea4dfcda4c05ad5a65d03378
SHA3-384 hash: 43f77d75471c70279012e8147539338cf4b6553bf460791acc49457bdab97915bf4972cb848de31b278d04c8ed183681
SHA1 hash: 66925fc2d0fc17ede7b180d708efac7d3f96df7f
MD5 hash: e0f5729f22d294d85b7a1fe5095df136
humanhash: minnesota-helium-charlie-equal
File name:o30c332m.exe
Download: download sample
Signature Dridex
File size:398'336 bytes
First seen:2020-10-05 21:04:42 UTC
Last seen:2020-10-05 22:20:45 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 015460f5308dc8498534430e941bfa0c (1 x Dridex)
ssdeep 6144:XydTZcdU3YdkR5p44v5RS2rTQbDyyL4vkysU4IchlAh8fNhtekzM+DK:qVx31/pXBRBPQay8qhe8f11DK
TLSH 1B84BF01F9D4D039E973423D5C6AE2A0857FBCD14F7419E733D99D8A0B3A580AE65E23
Reporter Anonymous
Tags:Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
197
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-05 19:03:55 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader evasion trojan discovery family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Checks installed software on the system
Checks whether UAC is enabled
Blacklisted process makes network request
Dridex Loader
Dridex
Malware Config
C2 Extraction:
85.114.134.25:443
94.23.45.86:3889
145.239.169.34:4643
162.212.152.222:3389
Unpacked files
SH256 hash:
a8b125a1162491b5a6d0a4372aea196007ba8f96ea4dfcda4c05ad5a65d03378
MD5 hash:
e0f5729f22d294d85b7a1fe5095df136
SHA1 hash:
66925fc2d0fc17ede7b180d708efac7d3f96df7f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll a8b125a1162491b5a6d0a4372aea196007ba8f96ea4dfcda4c05ad5a65d03378

(this sample)

  
Delivery method
Distributed via web download

Comments