MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4f32ff1f6a1a6db2497781d64c19868972dbc35be7ff881b63771c96a87a054. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b4f32ff1f6a1a6db2497781d64c19868972dbc35be7ff881b63771c96a87a054
SHA3-384 hash: c0d76dec1794789ef6eb3737e28c7367fb8cdcbbe7b292df77b83b2b21be54c0c44484b5b01d7fc12c4325feaae67b5d
SHA1 hash: c71f37cb3e0136d59742571677f3430fc4977c01
MD5 hash: e2e59a887b9ac298bee6f06962d72bcb
humanhash: princess-march-minnesota-cardinal
File name:mkcxskjd(1).exe
Download: download sample
Signature Dridex
File size:200'704 bytes
First seen:2020-06-23 13:55:28 UTC
Last seen:2020-06-23 15:21:16 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5f5d7f3d576b5fd54d7374e64458a706 (3 x Dridex)
ssdeep 6144:4QYmU2JFD8euKJ7lfJy7hcYrDZM8DY8gGTlj:4MU2z8NKJR8rDZM8D5
Threatray 262 similar samples on MalwareBazaar
TLSH 07140119778481B7F79694307D67F5B90A952C734814C66F1F82391CEEBEA2688F032B
Reporter JAMESWT_WT
Tags:Dridex

Intelligence


File Origin
# of uploads :
3
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-06-23 13:57:05 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments