🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8ef959a9176aef07fdca8705254a163b50b49a17217a4ff0107487f59d4a35d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Maldoc score: 4


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: b8ef959a9176aef07fdca8705254a163b50b49a17217a4ff0107487f59d4a35d
SHA3-384 hash: 353bbefd55bc4c0f08736fd2e6a2f39f319a1d92ffd2aed003cc483a3f823c2315efa9364653bb048d573deadc2f06af
SHA1 hash: 4d58ec4c978988f16468cda2323103ae62b2baea
MD5 hash: e63deaea51f7cc2064ff808e11e1ad55
humanhash: triple-salami-item-fanta
File name:Purchase_Order 2412.xls
Download: download sample
Signature Dridex
File size:84'480 bytes
First seen:2021-10-13 13:47:49 UTC
Last seen:2025-03-25 14:34:52 UTC
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 1536:LFk3hbdlylKsgqopeJBWhZFGkE+cL2NdAA5eSUPIbjB59ZYiosYvvXvTWbxgXTPE:LFk3hbdlylKsgqopeJBWhZFGkE+cL2Nn
TLSH T184835BA6F682E909D95917754CE683E26727FC115F53C38B7288F72F0F727808A03656
Reporter Anonymous
Tags:Dridex xls

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 4
OLE dump

MalwareBazaar was able to identify 14 sections in this file using oledump:

Section IDSection sizeSection name
1108 bytesCompObj
2248 bytesDocumentSummaryInformation
3184 bytesSummaryInformation
463199 bytesWorkbook
5427 bytes_VBA_PROJECT_CUR/PROJECT
662 bytes_VBA_PROJECT_CUR/PROJECTwm
75109 bytes_VBA_PROJECT_CUR/VBA/Sheet1
8999 bytes_VBA_PROJECT_CUR/VBA/ThisWorkbook
92895 bytes_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
101845 bytes_VBA_PROJECT_CUR/VBA/__SRP_0
11309 bytes_VBA_PROJECT_CUR/VBA/__SRP_1
121823 bytes_VBA_PROJECT_CUR/VBA/__SRP_2
13714 bytes_VBA_PROJECT_CUR/VBA/__SRP_3
14523 bytes_VBA_PROJECT_CUR/VBA/dir
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
SuspiciousRunMay run an executable file or a system command
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
10
# of downloads :
247
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Purchase_Order 6110.xls
Verdict:
No threats detected
Analysis date:
2021-10-13 12:11:01 UTC
Tags:
macros

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Document image
Document image
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
macros
Result
Threat name:
Detection:
malicious
Classification:
bank.troj.expl.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Detected Dridex e-Banking trojan
Document contains an embedded VBA macro with suspicious strings
Document exploit detected (drops PE files)
Document exploit detected (process start blacklist hit)
Document exploit detected (UrlDownloadToFile)
Found malware configuration
Office process drops PE file
Sigma detected: BlueMashroom DLL Load
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: Regsvr32 Anomaly
Sigma detected: Regsvr32 Command Line Without DLL
System process connects to network (likely due to code injection or exploit)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
Threat name:
Document-Office.Infostealer.Dridex
Status:
Malicious
First seen:
2021-10-13 11:13:02 UTC
AV detection:
15 of 41 (36.59%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Office loads VBA resources, possible macro or embedded object present
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Dridex

Excel file xls b8ef959a9176aef07fdca8705254a163b50b49a17217a4ff0107487f59d4a35d

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments