MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca1af46f8c8cabb97f3faa3fada54588ac1c5fcab8c599872d867b3b62d75fd9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ca1af46f8c8cabb97f3faa3fada54588ac1c5fcab8c599872d867b3b62d75fd9
SHA3-384 hash: ecbb770c77e01c8ded84156f02efff3bb7eac4bd23940ed1255fa67a96e18950f7a2eca4302d4be34d12fcda4f149e94
SHA1 hash: 694d4fc1fd59c78108b265398645eff5c97b5d6f
MD5 hash: 71f477dedf6350d7af0e576829cf753b
humanhash: happy-bacon-fish-table
File name:71f477dedf6350d7af0e576829cf753b.dll
Download: download sample
Signature Dridex
File size:204'605 bytes
First seen:2021-01-20 14:31:13 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 1536:mEJebxvsttWrdxgn7EfWTTw/azBIqIjPMf1NrbkmV/6z5fTm29sYBIEY0dO:mEkbRs3Afs0/oG81CmV/6zlticrYn
Threatray 196 similar samples on MalwareBazaar
TLSH 0C14BED80DE78DD7E8B3C0B3FA2D45B4752A1F851B6B0BD6CA66521C8A1340E1C5EA4F
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
141
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 342221 Sample: q25j7OlBa7.dll Startdate: 20/01/2021 Architecture: WINDOWS Score: 48 10 Multi AV Scanner detection for submitted file 2->10 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 6 9 6->8         started       
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2021-01-20 09:54:09 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
ca1af46f8c8cabb97f3faa3fada54588ac1c5fcab8c599872d867b3b62d75fd9
MD5 hash:
71f477dedf6350d7af0e576829cf753b
SHA1 hash:
694d4fc1fd59c78108b265398645eff5c97b5d6f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll ca1af46f8c8cabb97f3faa3fada54588ac1c5fcab8c599872d867b3b62d75fd9

(this sample)

  
Delivery method
Distributed via web download

Comments