🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5c188e82a1dad02f71fcb40783cd8b910ba886acee12f7f74c73ed310709cd2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: b5c188e82a1dad02f71fcb40783cd8b910ba886acee12f7f74c73ed310709cd2
SHA3-384 hash: dc2df3aa7302dadb6027388dcba911ce7c89091a286a75be794e6c074fc6852fdf2395d8e1c597911ed8e0f507a62799
SHA1 hash: eeecdd240ae03ffb38445d887418d63bf31bc2bc
MD5 hash: 41b279fa879354ce8a47970758efe40a
humanhash: mirror-fish-earth-kentucky
File name:b5c188e82a1dad02f71fcb40783cd8b910ba886acee12f7f74c73ed310709cd2.bin
Download: download sample
Signature Dridex
File size:233'472 bytes
First seen:2021-12-24 19:08:14 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash fb2de2087d1af165544b8819e84796cc (1 x Dridex)
ssdeep 3072:05jYx872M4Ctfz4xBTW5UFyUwqVqxXckZ6mCUi2+1UnNiQWUtlRjswqyZm/ZKfv:05i87j4CpzyW5cq+TmCUO1G7W+T1LoZ
Threatray 5'733 similar samples on MalwareBazaar
TLSH T19634E18AD7A664ECF85B55322146BA2F32246D235739ECE7CDC1C230FBB9915A433153
Reporter Arkbird_SOLG
Tags:dll Dridex Grief Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
840
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
67%
Tags:
doppelpaymer packed ransomware virus
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 545041 Sample: BYo6l8Xak6.bin Startdate: 24/12/2021 Architecture: WINDOWS Score: 64 25 Antivirus / Scanner detection for submitted sample 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Machine Learning detection for sample 2->29 31 Sigma detected: Suspicious Call by Ordinal 2->31 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 WerFault.exe 2 9 8->12         started        15 rundll32.exe 8->15         started        dnsIp5 17 rundll32.exe 10->17         started        23 192.168.2.1 unknown unknown 12->23 19 WerFault.exe 9 15->19         started        process6 process7 21 WerFault.exe 23 9 17->21         started       
Threat name:
Win32.Ransomware.DoppelPaymer
Status:
Malicious
First seen:
2021-07-10 10:01:00 UTC
File Type:
PE (Dll)
AV detection:
22 of 27 (81.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
0b1900a7a739a00b69c0332e567a8ed800349ad9381865b50d183dadec67a33d
MD5 hash:
2188545fc8d3a7f13dff58a58ef128b8
SHA1 hash:
b24a74380d175f76b0058929a181c795dd956a19
Detections:
win_dridex_auto
SH256 hash:
84901780b0f1e9b773cc536cea98d3bffec8819321e9283c6e269c0b8955d60e
MD5 hash:
7672554e57c1e383376104cb18c73022
SHA1 hash:
599c3898333dfe5947fe334193dea3a04e2276bd
Detections:
win_doppelpaymer_auto
SH256 hash:
b5c188e82a1dad02f71fcb40783cd8b910ba886acee12f7f74c73ed310709cd2
MD5 hash:
41b279fa879354ce8a47970758efe40a
SHA1 hash:
eeecdd240ae03ffb38445d887418d63bf31bc2bc
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments