MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d43f1cec696053a2a439808d02f4efcf26b312bd4f7f06e4fb8407613df1d4aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d43f1cec696053a2a439808d02f4efcf26b312bd4f7f06e4fb8407613df1d4aa
SHA3-384 hash: aa20f9abe9ef0fb0c1f9348afe7c195e4c0ef9beb444aa179bf300b23dedd952c092cc554debd292fe1c22b58265c1df
SHA1 hash: b3d4188d6e79b1f143c73c30b3686339eac76051
MD5 hash: b10dc606a95fdedecaaa11552c31bca1
humanhash: twenty-fish-uranus-papa
File name:Dridex.ps1
Download: download sample
Signature Dridex
File size:7'013 bytes
First seen:2020-12-08 10:07:13 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 192:yhbfaT62NtpcZL8EUkPSAS6KeihiXWoht:yhwvrpcZox3Lh6Woht
Threatray 198 similar samples on MalwareBazaar
TLSH DEE1E7E2AE37FE9401D7B1E90FD3388D11109A63527892F8A34D08D7A66C506EF1A7F5
Reporter JAMESWT_WT
Tags:Dridex ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
272
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Threat name:
Script-PowerShell.Infostealer.Dridex
Status:
Malicious
First seen:
2020-12-08 10:08:05 UTC
File Type:
Text
AV detection:
5 of 29 (17.24%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments