MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b325eab59c4e9bd54a0f63a37f3bfdaf85a35244a9720207302b69190d628db6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b325eab59c4e9bd54a0f63a37f3bfdaf85a35244a9720207302b69190d628db6
SHA3-384 hash: dde344fb429355bb9629cd44c5b0863a2bb3617a9253e030d83151307e8752331d79bf88316d8f795520067c6f87221e
SHA1 hash: 69c18ec9f2803c9cc6aba55520aed2df6c2d7bd9
MD5 hash: 8533b6c949253b5027378b2508414502
humanhash: golf-moon-video-enemy
File name:8533b6c949253b5027378b2508414502.dll
Download: download sample
Signature Dridex
File size:337'241 bytes
First seen:2020-10-16 14:25:45 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 6144:S3s9vfpA09TUZiYWpcl8Yte2YMnnWZI8VQ3SSOED1nUmhMwHpId7XGI:Sc9vDhUZiYWpcl80YMnv3YERntMwHpq5
Threatray 23 similar samples on MalwareBazaar
TLSH 88742A06FBC40E77C9CB3176C4591177827BEE9507A5FA0357B9B948DAB13E93B20A02
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-10-11 14:22:32 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
b325eab59c4e9bd54a0f63a37f3bfdaf85a35244a9720207302b69190d628db6
MD5 hash:
8533b6c949253b5027378b2508414502
SHA1 hash:
69c18ec9f2803c9cc6aba55520aed2df6c2d7bd9
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll b325eab59c4e9bd54a0f63a37f3bfdaf85a35244a9720207302b69190d628db6

(this sample)

  
Delivery method
Distributed via web download

Comments