MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6d737cec7b0cacc3ddcd3e6d2a8d40adbbd95e9676aabaf80b1e2120e04a89d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d6d737cec7b0cacc3ddcd3e6d2a8d40adbbd95e9676aabaf80b1e2120e04a89d
SHA3-384 hash: f06778f4bee14e823155f732d96bf08ca05a1e84d975f67fe45670ee3366d2025d910b29c79ed39cd95919fcb558d7c3
SHA1 hash: 6e73f2c46d534c52f680629e02755069df83f87c
MD5 hash: bdb3a5e5c310100aae2c9f290b732c4d
humanhash: michigan-kentucky-beer-zebra
File name:3qzv0g3q
Download: download sample
Signature Dridex
File size:314'368 bytes
First seen:2020-06-29 13:06:17 UTC
Last seen:2020-06-29 14:14:39 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 42c1c47ebfea727d68b2c58f3200c802 (3 x Dridex)
ssdeep 6144:kSWHIuBYFVpvhnJ8Q49Zh4TbXamNk03aH37fJ:6ZYbpvhOQKhqrt5GLfJ
Threatray 211 similar samples on MalwareBazaar
TLSH 3E64D15236D0D4B5D4A746B18E64E1BA86E9FD61EE308C4337CC5F8F6A21DD0C23AB52
Reporter JAMESWT_WT
Tags:Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
107
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-06-29 13:08:06 UTC
File Type:
PE (Dll)
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
evasion trojan discovery
Behaviour
Suspicious use of WriteProcessMemory
Checks whether UAC is enabled
Checks for installed software on the system
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments