MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2fc2c0e222c88b45df343109a204a46b60d85f56e9fbfd9527e18f693469412. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: b2fc2c0e222c88b45df343109a204a46b60d85f56e9fbfd9527e18f693469412
SHA3-384 hash: 22f1b427d285d09e70252668c90b0b076cf9a52d856c7a3543e1009b6bd8b7c46e088abc4d5b8735b99282d47e3accaf
SHA1 hash: c7f71586d29977d2baa1f38e8c60c784f8ebd65c
MD5 hash: 4abd69a2b897be69427cf872117e83b9
humanhash: hot-football-helium-monkey
File name:Subconract 504.zip
Download: download sample
Signature Dridex
File size:776'798 bytes
First seen:2021-02-22 16:36:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:4au7L8TbBWoks81K3wCbMOK+A2+4LkeD5eR6FElQ6ixjinam5/0xjm3ZWWUKi:4auM5Woks81KgZGN+SIR6FEl9kqd/0xn
TLSH 65F4231A3D2AD0E0EA43C4E7680510CB50AFA4A8D5F8F30FABDDD6407EFA5550D6D6CA
Reporter cocaman
Tags:encrypted zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
144
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Dridex

zip b2fc2c0e222c88b45df343109a204a46b60d85f56e9fbfd9527e18f693469412

(this sample)

  
Delivery method
Distributed via e-mail link

Comments



Avatar
Corsin Camichel commented on 2021-02-22 16:38:15 UTC

Password: 4S4A6