🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba01a2cb78c39adf8042c658ac9c193a663e7f3311864763dd2b8ba400a93249. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments 1

SHA256 hash: ba01a2cb78c39adf8042c658ac9c193a663e7f3311864763dd2b8ba400a93249
SHA3-384 hash: 394968bd28b15e39fcfa12c71e24d3cd5906931193bbe597c6b4bd81eaac8fd63af05d320dc270786af7f4c68b1fbd7a
SHA1 hash: 3c729b379ebbe02683a88d6b3846188616388818
MD5 hash: 3e2881e591904f85336d7e37f781f7c2
humanhash: connecticut-freddie-oregon-asparagus
File name:3e2881e591904f85336d7e37f781f7c2
Download: download sample
Signature Dridex
File size:536'576 bytes
First seen:2021-12-13 21:57:37 UTC
Last seen:2021-12-13 23:38:40 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash e9192d34e4c9dcdf739aaa1d74025eb2 (27 x Dridex)
ssdeep 6144:ZKMImhktm7mnmvetmzK/kxwv4Zm7mREqZzdazdULd54f3X0kdVtL8faGAPlX:Z9hXAg5aX0CL8fI
Threatray 5'589 similar samples on MalwareBazaar
TLSH T10CB4B0D1F05FE94AFA5E46712E189932D45E0B03A3A6BB787623402C66DD3253CD2B72
Reporter zbetcheckin
Tags:32 dll Dridex exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
179
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
67%
Tags:
greyware packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Tries to delay execution (extensive OutputDebugStringW loop)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 539245 Sample: s4SPcSAmyJ Startdate: 13/12/2021 Architecture: WINDOWS Score: 80 22 162.241.33.132 UNIFIEDLAYER-AS-1US United States 2->22 24 217.160.5.104 ONEANDONE-ASBrauerstrasse48DE Germany 2->24 26 2 other IPs or domains 2->26 28 Found malware configuration 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Dridex unpacked file 2->32 34 3 other signatures 2->34 9 loaddll32.exe 1 2->9         started        signatures3 process4 signatures5 36 Tries to delay execution (extensive OutputDebugStringW loop) 9->36 12 cmd.exe 1 9->12         started        14 rundll32.exe 9->14         started        process6 process7 16 rundll32.exe 12->16         started        18 WerFault.exe 9 14->18         started        process8 20 WerFault.exe 23 9 16->20         started       
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-12-13 21:58:12 UTC
File Type:
PE (Dll)
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
104.36.167.47:443
188.40.48.93:4664
162.241.33.132:9217
217.160.5.104:593
Unpacked files
SH256 hash:
c686a5de9da71d1769fe4e1195ba14e317de39c4949cb5448bed458772b80351
MD5 hash:
47d185c3447007095ad4efabab5643cf
SHA1 hash:
eaa868a64149909426cc47583ddae9f9f08c0ba2
Detections:
win_doppeldridex_auto
SH256 hash:
48d3a64c501f161c1436933c5f98dea6911f88a48ec445eada05f67e87c1d78d
MD5 hash:
1b22f613a65698007fe993b30d43ab5e
SHA1 hash:
7bb2291535ce8e20094d762e9535e4dc68db469f
Detections:
win_dridex_auto
Parent samples :
ddb7acdcdb339543380bcb3d4633248ffe20e555104b26999a4c2ae2a40dfa14
7a26d1b438379d5d2aab546f7753bd4df2593680755e8595bfa11dce1ccc1c12
765b54b871cee0938ec705329d96c028d64fdd3234182060333415613b7eb7f4
bc9379090bc8de95b1f765cd41ddd45043e2fdceb86ed2dd0e4d988600baae85
104f26193555cb12c6738ed0fdddf4fb609c241b75192ec24856d077a3ca490e
afd3d540c9806ec47ae8e234368b513b16265e33ca487b9c54e1e435d70aaea0
02b4e73080d8846e3a1e57a00f0f332a68df4355d14be50811f62c50f03830c2
5c17631af38e9a8910015e2ca160a7d9505c9ca8863be9258b3e30411301a03f
3ccdc391b7cab2de27453c65ce062cda1f4020d110ff4c20323484f9910507e7
c93073bdd03e0b2771da3997ba7fe5aff86edf2c682d70b5be4bd3d2d30ee5b1
2188ba59be5637dbc7e38dbf6eb379d43a1c62eaa3301cbfc680b02c5a36c023
ba01a2cb78c39adf8042c658ac9c193a663e7f3311864763dd2b8ba400a93249
b24c3ed00e59dbcff18037648cad503072b9e0d7a13f30d2bbfa9c466fdbee66
59ac15b6de9e5065e58ccc24797e3bb36e2a4eb4348e83979781cc880a3456c0
3aab8f6eca123b1fc8184caa6ad3320ac6c9f58cd73835fac41feef05053abff
de4ced01e9e13a297adb61c70746296d1e22b3d09cf7534f9ebdb16e82684823
32f8a7972ce0593b753c37f18cce172e3ca2fdca15a0ea6ae6f392fd388a2e20
e8b40e350941513e25125bda776582af0ab862f06648792424c924d1dc001875
65a5017e05c78e8fa52197912f8b1003e06071321ec1b46859f8581d372d2959
6477f31e018582791a793ff0c0273f9f2b43139c0b25a88772cb90a72111f6bb
492fe6caf5e12dcb484f636079c246fbf0ab4b8ed59e8e5a61131dbd1fd4d2be
a7919340edfbafcf10751579a93ee23b1fe864d9680d553bd254422d14ffeeb0
bf3130e116fd5d9ae43a09831d59f66acee6cb0de1d657e80e711a2bb6397408
95d1beab5c48ef14f201aa49b734444ecc9dc9516d950f4c3cef8eadc0d9fbba
0341b7e0b66e27bee166ba1fd9fad700d85e58a257bbfed1b60a662d97fc1617
1bd2e431f2631a5bfc21a9e244bb28d4230dad825b9d6396afcd32458923fb0a
e4db910a4147ac44bef76f71e6b0d6bd193b89a6268dda35f3b1c210cc111fe4
48d3a64c501f161c1436933c5f98dea6911f88a48ec445eada05f67e87c1d78d
SH256 hash:
ba01a2cb78c39adf8042c658ac9c193a663e7f3311864763dd2b8ba400a93249
MD5 hash:
3e2881e591904f85336d7e37f781f7c2
SHA1 hash:
3c729b379ebbe02683a88d6b3846188616388818
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:dridex_loader
Author:kevoreilly
Description:Dridex Loader
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:win_doppeldridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppeldridex.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll ba01a2cb78c39adf8042c658ac9c193a663e7f3311864763dd2b8ba400a93249

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-12-13 21:57:39 UTC

url : hxxp://intwelius.com/D89D/EsRXNEmlPdickpenis.bin