MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 baeda885f0ceae133ec9c94c167e94f612f8fd21b678b2a23ff3638904123d52. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: baeda885f0ceae133ec9c94c167e94f612f8fd21b678b2a23ff3638904123d52
SHA3-384 hash: 16f0a068042f7ff228c3b02d91dc5b05070a6dcf4e4bdab7d53e8ddd4bf08c6a8d12d17514a790837f1075814536ba46
SHA1 hash: 6895bbd732f25c4088a3aa9e31167a712b913e61
MD5 hash: f9b71816fc9ddf2b2c7d1a1574576b3c
humanhash: wolfram-leopard-uranus-hotel
File name:f9b71816fc9ddf2b2c7d1a1574576b3c.dll
Download: download sample
Signature Dridex
File size:17'093 bytes
First seen:2020-10-16 14:25:50 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 192:fjyZV8OWntLk3ysRSBx6MrrGXA55gaby7Ga58VH1Lqv1ewW94qR7kV:fjy0ntLE43PcOWGVqBW38
Threatray 23 similar samples on MalwareBazaar
TLSH A1723006C5D5D6F0C5AAE1B9997BD0681B2359E3931878E643F1AB2EDF07D026F30E81
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2020-10-15 13:29:55 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
baeda885f0ceae133ec9c94c167e94f612f8fd21b678b2a23ff3638904123d52
MD5 hash:
f9b71816fc9ddf2b2c7d1a1574576b3c
SHA1 hash:
6895bbd732f25c4088a3aa9e31167a712b913e61
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll baeda885f0ceae133ec9c94c167e94f612f8fd21b678b2a23ff3638904123d52

(this sample)

  
Delivery method
Distributed via web download

Comments