MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3bb51237eb75fceb5a9ecf67ca05542dbf1a12d9ea199f9217a3e50e1d7800f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b3bb51237eb75fceb5a9ecf67ca05542dbf1a12d9ea199f9217a3e50e1d7800f
SHA3-384 hash: 8f9a7bcee2926276b74ecb599a8c4b75dfe5735c71c4e97e3ac47ef48c45277178254d06a13662b34593fc5854b3e15e
SHA1 hash: 93e370d845e68d0d7cd410d2f6f37f08d259c1a7
MD5 hash: 3f0bfcb42a325dfb4b455d783751866d
humanhash: carpet-sodium-wolfram-mirror
File name:3f0bfcb42a325dfb4b455d783751866d.dll
Download: download sample
Signature Dridex
File size:540'672 bytes
First seen:2020-11-28 11:11:47 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 108c03d319577150f623cda6e1e3914f (4 x Dridex)
ssdeep 6144:7+dBKd3douH2Hnfe1DAXxlzn15BnyR1vwVYhQU7:6do1i21sBlDpyR19h7
Threatray 13 similar samples on MalwareBazaar
TLSH 24B4D494BDA91261E4AD0D32664779AB05DB3443FB73712626E73FE0E4B01B43DBA321
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
257
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 324152 Sample: RY4Tp6CiSN.dll Startdate: 28/11/2020 Architecture: WINDOWS Score: 52 11 g.msn.com 2->11 13 Multi AV Scanner detection for submitted file 2->13 15 Machine Learning detection for sample 2->15 7 loaddll32.exe 1 2->7         started        signatures3 process4 process5 9 WerFault.exe 6 9 7->9         started       
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2020-11-28 11:12:07 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
b3bb51237eb75fceb5a9ecf67ca05542dbf1a12d9ea199f9217a3e50e1d7800f
MD5 hash:
3f0bfcb42a325dfb4b455d783751866d
SHA1 hash:
93e370d845e68d0d7cd410d2f6f37f08d259c1a7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll b3bb51237eb75fceb5a9ecf67ca05542dbf1a12d9ea199f9217a3e50e1d7800f

(this sample)

  
Delivery method
Distributed via web download

Comments