MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c475b446e6d620ade6d55ef6eb7f75d29e2be8db678ca4df0254f355ec3b7e74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c475b446e6d620ade6d55ef6eb7f75d29e2be8db678ca4df0254f355ec3b7e74
SHA3-384 hash: 863d3deae01f7d091a44d65465fc41e4e7629609b32d5811c3882b8493869c3768556149c4f3c2cd45c89fab33704ce1
SHA1 hash: 1cf0d3692de36d60cf4b8f669d0ec2ddcc572afe
MD5 hash: bf193dc55277cf52ea72b86e6a688887
humanhash: zebra-oscar-black-crazy
File name:7zcsfotxt
Download: download sample
Signature Dridex
File size:331'776 bytes
First seen:2020-09-09 10:12:52 UTC
Last seen:2020-09-09 10:37:31 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 2cab58e57e2dc442524d4dc15c61cdab (3 x Dridex)
ssdeep 6144:V9UaMVbo0KJkrc7vmGzMB5Xps+62b1NR+1Njo1N/Q1N2xA:nUa2nKyrc7vDoBta+7ZNRQNjiN/qNSA
Threatray 58 similar samples on MalwareBazaar
TLSH 6964D04163EB204DF4BFBFF2A4798245ACBE7C958438455DE320085F42BA2B6895EF71
Reporter JAMESWT_WT
Tags:Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
181
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2020-09-09 10:14:08 UTC
File Type:
PE (Dll)
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Dridex Loader
Dridex
Malware Config
C2 Extraction:
67.213.75.205:443
186.103.215.157:33443
185.201.9.197:9443
108.175.9.22:33443
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll c475b446e6d620ade6d55ef6eb7f75d29e2be8db678ca4df0254f355ec3b7e74

(this sample)

  
Delivery method
Distributed via web download

Comments