MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6d040e757222c867b6ea6ce6a01b1c4bd267e3dfbe776434a36e8c9bb50e389. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d6d040e757222c867b6ea6ce6a01b1c4bd267e3dfbe776434a36e8c9bb50e389
SHA3-384 hash: b4f25c41b6d4b49cee3c64e871037f0b35fb30a51033b8aaaca6a05a99835c551fde5be1c834e003acbb6ab62d71b52f
SHA1 hash: 8d14059f852d617db8451608b8d3057ea97126ff
MD5 hash: 25ca90096605bd0fbbdab42f992c87ed
humanhash: low-india-washington-tennis
File name:25ca90096605bd0fbbdab42f992c87ed.dll
Download: download sample
Signature Dridex
File size:523'707 bytes
First seen:2020-11-12 09:17:45 UTC
Last seen:2024-07-24 21:55:48 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 07399ad339cf595a6fce2b97280a6dac (3 x Dridex)
ssdeep 6144:pNYqD+68wrhr7fCzZmYg5yu6fOj8AOez94M1VYT+Lg+Jb6Be1YBlT5htgyCoAekZ:x58wFrimdFIAhzW2VYTdSGbNNJCoO
Threatray 1 similar samples on MalwareBazaar
TLSH 6EB45A023641842CF71F8F3D8847D1F56AC6BCA35A397AE736C90E97DB2724399A1742
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
3
# of downloads :
114
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 315269 Sample: YJL3IPAQlz.dll Startdate: 12/11/2020 Architecture: WINDOWS Score: 48 13 Multi AV Scanner detection for submitted file 2->13 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 6 9 6->8         started        dnsIp5 11 192.168.2.1 unknown unknown 8->11
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-11-12 09:18:08 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
d6d040e757222c867b6ea6ce6a01b1c4bd267e3dfbe776434a36e8c9bb50e389
MD5 hash:
25ca90096605bd0fbbdab42f992c87ed
SHA1 hash:
8d14059f852d617db8451608b8d3057ea97126ff
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll d6d040e757222c867b6ea6ce6a01b1c4bd267e3dfbe776434a36e8c9bb50e389

(this sample)

  
Delivery method
Distributed via web download

Comments