MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bce8828ca6641e52c061074e1190cbe058195cf51b91b22ae915043826a69831. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bce8828ca6641e52c061074e1190cbe058195cf51b91b22ae915043826a69831
SHA3-384 hash: 86907cc44d0852632bb938aaabb9222b5a2d024c07983697825510acc6666d86beefb85e24547a54c72b9374ea80a27f
SHA1 hash: 10e81a92bcb48d7c779dd60a2267cabcc01b3881
MD5 hash: b854736ab49be9c3d458c56c308d5e89
humanhash: steak-fanta-wyoming-utah
File name:vertusa.dll
Download: download sample
Signature Dridex
File size:379'904 bytes
First seen:2020-06-23 12:13:11 UTC
Last seen:2020-06-23 13:10:14 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 50675127913b2201517773e1660b5e8d (1 x Dridex)
ssdeep 6144:xQ5p8Cp9isq+x7ByxYr1t2sAH+CXA92hLj4oq6GNDnYAbTeFEa:yFp+O8sisAHBQI4oq/NDnyEa
Threatray 24 similar samples on MalwareBazaar
TLSH 3284C011B742C076E2A2763E5816E7799A2DFDD04F3828D732CC1D87E9E72805B39A53
Reporter JAMESWT_WT
Tags:Dridex

Intelligence


File Origin
# of uploads :
4
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-23 12:14:09 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery evasion trojan
Behaviour
Suspicious use of WriteProcessMemory
Checks for installed software on the system
Checks whether UAC is enabled
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments