🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be3eb491dd9953d6d06879a99357613f2a837f8a79a2ac3b67dfe7e6ce2bfdec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments 1

SHA256 hash: be3eb491dd9953d6d06879a99357613f2a837f8a79a2ac3b67dfe7e6ce2bfdec
SHA3-384 hash: 8815fe77b5e41951eff0a8bb6a3db740f2a8a7b2e60cf30fd946468bc0104e808f1e8a73f64247b2455bbe125af3d254
SHA1 hash: 062249b1a47ba13363f99b00d667dde77ef68d03
MD5 hash: b04446e8c3b7ff393c5d5d75248d8b8a
humanhash: indigo-west-bacon-fourteen
File name:b04446e8c3b7ff393c5d5d75248d8b8a
Download: download sample
Signature Dridex
File size:663'552 bytes
First seen:2021-11-18 03:54:53 UTC
Last seen:2021-11-18 06:03:16 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash fe16443ce39f2fcea9c5accdb27a9eac (21 x Dridex)
ssdeep 12288:HjTlJzJzJBJZn/JH3lJxJLJZJdPgA1VKBUA1rlldNJw:HjJtpDv/lVbdT3IA1wBUA1rlldNK
Threatray 5'366 similar samples on MalwareBazaar
TLSH T1DDE48E0250D512FCFA898ABF155A67C1C6B310824ED1CB9E25CD07EADF64A03EE6D1B7
Reporter zbetcheckin
Tags:32 dll Dridex exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
72 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 524154 Sample: J9GMTO4Amo Startdate: 18/11/2021 Architecture: WINDOWS Score: 72 17 54.37.70.105 OVHFR France 2->17 19 142.93.218.86 DIGITALOCEAN-ASNUS United States 2->19 21 2 other IPs or domains 2->21 23 Found malware configuration 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Yara detected Dridex unpacked file 2->27 29 2 other signatures 2->29 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        process6 13 rundll32.exe 11->13         started        process7 15 WerFault.exe 23 9 13->15         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-18 03:55:07 UTC
AV detection:
18 of 45 (40.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22203 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
54.37.70.105:443
198.199.70.22:6602
164.68.99.3:5007
142.93.218.86:4664
Unpacked files
SH256 hash:
f2090441a3bb393952769954320b43e892f8f98fc22c5dd78b7ed5807e53a214
MD5 hash:
2d4aaa2262517e505f52b13858dbde52
SHA1 hash:
72523dbd72452c8dacaa070f05c9145741571301
Detections:
win_doppeldridex_auto
SH256 hash:
2e4da7dbe3d43e07cf011302db7302f7b8d632d6823966ee620ae30cf34662e7
MD5 hash:
fffeb707e430160c6d8914689e04389b
SHA1 hash:
5537b9332c0efbfae10f9b433bb851959bd11cc7
Detections:
win_dridex_auto
SH256 hash:
be3eb491dd9953d6d06879a99357613f2a837f8a79a2ac3b67dfe7e6ce2bfdec
MD5 hash:
b04446e8c3b7ff393c5d5d75248d8b8a
SHA1 hash:
062249b1a47ba13363f99b00d667dde77ef68d03
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll be3eb491dd9953d6d06879a99357613f2a837f8a79a2ac3b67dfe7e6ce2bfdec

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-11-18 03:54:55 UTC

url : hxxps://fmbrsa.am.files.1drv.com/y4maex-Uyqd9oStQeDPhrf4hWMEQrzzWE_2nhUzsTS_WynGmNGnqEemW1vjWncETQBNO9cpVGD7dtXKejqUZVJpqhK9mZeakZPuS9O5sZgMuGK1Hf0U1MlUXyQfMtzBatq-iBzJ6jSfpemwJ-C2biGeDZ1yNdrWH39UIW3tlaJAMfmvw4xG_9DBroRBWm2aSt3SyQy6k1_ESD1MQs5AVUbYVQ/fphcamwogqi.mp4