🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc241b69a19ac9a2fa9ab49f1ced7e04f3d3e4ec84a3c5baf874818469da1d7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: cc241b69a19ac9a2fa9ab49f1ced7e04f3d3e4ec84a3c5baf874818469da1d7c
SHA3-384 hash: 32f676833f1aaf0cc6d4ced356b64daacfddf0e5f37dd200dbf18621b6127cf0ceedd11b89145dc85d6799879c0c6910
SHA1 hash: d47573961aa57859e87490dcfc59f64b90fd749f
MD5 hash: 9794055d4259d7b5d91dd6a1782ab156
humanhash: skylark-saturn-kentucky-hawaii
File name:Sales_Receipt 5606_xls_PW_infected.zip
Download: download sample
Signature Dridex
File size:57'762 bytes
First seen:2023-04-04 03:33:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 1536:sUkRO03HVqWhhe07eBilnDMNc5qqcT2MnXJoadmq0mHonLxXno7cw:sUkNI4jGiET2MZpOpLxYgw
TLSH T1D84302173B8A1A091906FF58F06CBACF583DC428A97DD930DDBFD85A1889343F196E49
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter UniMatrix85
Tags:Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
313
Origin country :
SG SG
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Sales_Receipt 5606.xls
File size:84'480 bytes
SHA256 hash: b8ef959a9176aef07fdca8705254a163b50b49a17217a4ff0107487f59d4a35d
MD5 hash: e63deaea51f7cc2064ff808e11e1ad55
MIME type:application/vnd.ms-excel
Signature Dridex
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
dridex evasive macros obfuscated regsvr32 sload xlm
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Office loads VBA resources, possible macro or embedded object present
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments