MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ca087f46f97cd465f46e4ccb04181e6eae7b2c751ae7fd9e262191b979728ccc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 13
| SHA256 hash: | ca087f46f97cd465f46e4ccb04181e6eae7b2c751ae7fd9e262191b979728ccc |
|---|---|
| SHA3-384 hash: | d917703f2df6816ac057d51f26060eaf152ff5f2ecc955ea37916050574ce1d0493aea75724de7493fa6b7b8f2ba37e8 |
| SHA1 hash: | 13cbfa1d79184d1cea84aef59e5c856117fd91c2 |
| MD5 hash: | 6285579d7082c55871b4b9dbe735255a |
| humanhash: | south-kilo-batman-indigo |
| File name: | ca087f46f97cd465f46e4ccb04181e6eae7b2c751ae7fd9e262191b979728ccc |
| Download: | download sample |
| Signature | Dridex |
| File size: | 208'896 bytes |
| First seen: | 2022-08-30 18:28:05 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | cdadd24365a6c20de1ab1c7bb5385624 (1 x Dridex) |
| ssdeep | 6144:WG5/IZRVkgnLZf0V+H6fkmIF1nR5m0b+:W8/IZRyC500afUDh |
| Threatray | 55 similar samples on MalwareBazaar |
| TLSH | T1AD1412A92B65B64DF46B03B0C4FB57720260AE1EC0047E5EE55EDEDFCEF23258069618 |
| TrID | 32.2% (.EXE) Win64 Executable (generic) (10523/12/4) 20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.4% (.EXE) Win16 NE executable (generic) (5038/12/1) 13.7% (.EXE) Win32 Executable (generic) (4505/5/1) 6.2% (.EXE) OS/2 Executable (generic) (2029/13) |
| Reporter | |
| Tags: | Dridex exe |
Intelligence
File Origin
# of uploads :
1
# of downloads :
351
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
feb_inv_749726.doc
Verdict:
Malicious activity
Analysis date:
2020-02-19 15:54:42 UTC
Tags:
encrypted loader
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
DridexV4
Result
Verdict:
Malware
Maliciousness:
Behaviour
Searching for the window
Сreating synchronization primitives
Result
Malware family:
n/a
Score:
5/10
Tags:
n/a
Behaviour
MalwareBazaar
CheckCmdLine
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
packed
Malware family:
Dridex
Verdict:
Malicious
Detection:
dridex
Threat name:
Win32.Trojan.Zenpak
Status:
Malicious
First seen:
2020-02-19 16:49:30 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
31 of 41 (75.61%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
dridex
Similar samples:
+ 45 additional samples on MalwareBazaar
Result
Malware family:
n/a
Score:
1/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Unpacked files
SH256 hash:
2805660cc556fe0606c9b76a08e9c032092c90eaabe9f3c0aac46313f98f612d
MD5 hash:
be96a0910eb1987c167f7c2f51f69b74
SHA1 hash:
8ff3d4694c376bf5736a79ff070ff423e17be4c5
Detections:
win_dridex_g2
win_dridex_auto
SH256 hash:
ca087f46f97cd465f46e4ccb04181e6eae7b2c751ae7fd9e262191b979728ccc
MD5 hash:
6285579d7082c55871b4b9dbe735255a
SHA1 hash:
13cbfa1d79184d1cea84aef59e5c856117fd91c2
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Dridex
Score:
0.90
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.