🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2b43eefd7ae4cedb7d504f44ccdba410d0465017a92becfbc9730e57893671d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: b2b43eefd7ae4cedb7d504f44ccdba410d0465017a92becfbc9730e57893671d
SHA3-384 hash: bb1998d49a26df7891165e2ede5af92c5174f13feaebf584a73c0c2f3216068916ab99881d3084fdc7fd22eff9f8488a
SHA1 hash: 8d57dcc480124967f2e286bcff84d030148da680
MD5 hash: ac29dcd7fd74816cd403eafbffef42ef
humanhash: avocado-uranus-white-kansas
File name:Dridex dll (12)
Download: download sample
Signature Dridex
File size:663'552 bytes
First seen:2021-11-17 15:09:57 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 6ee6d183d3880a500fe4c20e1521f405 (17 x Dridex)
ssdeep 12288:SyDgTeyLeMTeGPeWnyyju+JUEleC5MK5q6JeY/eeFeajgcNagjycdeajOqHeiZWo:SIgayCMaGWWyyi+eEoCGKE68YGeIaEcn
Threatray 5'340 similar samples on MalwareBazaar
TLSH T1B1E4BF94A4DAB6CFD613DB75A4F1E7878C7E184CC2304FAEC052C69990E4B95023E79B
Reporter JAMESWT_WT
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
165
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 523834 Sample: Dridex dll (12) Startdate: 17/11/2021 Architecture: WINDOWS Score: 72 17 54.37.70.105 OVHFR France 2->17 19 142.93.218.86 DIGITALOCEAN-ASNUS United States 2->19 21 2 other IPs or domains 2->21 23 Found malware configuration 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Yara detected Dridex unpacked file 2->27 29 2 other signatures 2->29 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        process6 13 rundll32.exe 11->13         started        process7 15 WerFault.exe 23 9 13->15         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-17 15:10:13 UTC
AV detection:
15 of 44 (34.09%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22202 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
54.37.70.105:443
198.199.70.22:6602
164.68.99.3:5007
142.93.218.86:4664
Unpacked files
SH256 hash:
00db1d41ae6d59959bf7c74e49bd6c46deff393f555a953570e59ff074bf0bcc
MD5 hash:
9dd7f9cfc49735f2022147b33ba59087
SHA1 hash:
b6b76719ea1630ef85e33b97a4bff77cbc34c7b0
Detections:
win_doppeldridex_auto
SH256 hash:
b2b43eefd7ae4cedb7d504f44ccdba410d0465017a92becfbc9730e57893671d
MD5 hash:
ac29dcd7fd74816cd403eafbffef42ef
SHA1 hash:
8d57dcc480124967f2e286bcff84d030148da680
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll b2b43eefd7ae4cedb7d504f44ccdba410d0465017a92becfbc9730e57893671d

(this sample)

  
Delivery method
Distributed via web download

Comments