🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5dfcc4ef560b51ebe035a7846d6dede20c9f3f825f889bcbf6ac395bb0a745c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b5dfcc4ef560b51ebe035a7846d6dede20c9f3f825f889bcbf6ac395bb0a745c
SHA3-384 hash: dbd2373e626eba97b1385526952c7c458547f7dfd8d07c1072ef5adb494882f5fbba53c5d418612cdb1c015310e9150a
SHA1 hash: 051004eb4db4e096d0c601661e7e73371ff8a869
MD5 hash: 44de8ec765c645d2c6a57b7feae6c505
humanhash: summer-avocado-artist-bravo
File name:44de8ec765c645d2c6a57b7feae6c505.dll
Download: download sample
Signature Dridex
File size:45'056 bytes
First seen:2021-02-23 17:22:55 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 296c5ce0ec7abebda668048df2df9b05 (17 x Dridex)
ssdeep 384:C4qNPYZjPbiqDmlrawAvmLIA7JS52+l4YRO/8k75xc5NzsnNmjzCzeWqot7atXCk:NZjWqilRLHqu16NzsnwjzCqot7sZ
Threatray 32 similar samples on MalwareBazaar
TLSH 50135B04DBDFD0EAE80215B4017A7A3B76346E06C31DCEB6EF509F93D0B6681B47A248
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 356893 Sample: OQrRSWWHlj.dll Startdate: 23/02/2021 Architecture: WINDOWS Score: 23 34 Machine Learning detection for sample 2->34 14 loaddll32.exe 1 2->14         started        process3 process4 16 rundll32.exe 14->16         started        process5 18 rundll32.exe 16->18         started        process6 20 rundll32.exe 18->20         started        process7 22 rundll32.exe 20->22         started        process8 24 rundll32.exe 22->24         started        process9 26 rundll32.exe 24->26         started        process10 28 rundll32.exe 26->28         started        process11 30 rundll32.exe 28->30         started        process12 32 rundll32.exe 30->32         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-02-23 17:23:06 UTC
AV detection:
20 of 47 (42.55%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
b5dfcc4ef560b51ebe035a7846d6dede20c9f3f825f889bcbf6ac395bb0a745c
MD5 hash:
44de8ec765c645d2c6a57b7feae6c505
SHA1 hash:
051004eb4db4e096d0c601661e7e73371ff8a869
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll b5dfcc4ef560b51ebe035a7846d6dede20c9f3f825f889bcbf6ac395bb0a745c

(this sample)

  
Delivery method
Distributed via web download

Comments