MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6ddd24040b1f1ae7f42c84ee15f52efa36054e7ed4bb47d177d6b5108c9e5f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d6ddd24040b1f1ae7f42c84ee15f52efa36054e7ed4bb47d177d6b5108c9e5f6
SHA3-384 hash: 61300787362678893753fb984d6f01cdb55e0042b97b14650c0cad11125633b1fc2bc150ec38ce665bb265252dbb49ed
SHA1 hash: 0c8f8ec1f08bc7bb324293a1278556a379fd6b75
MD5 hash: d39acb349cd89c22d3ddf69b5cda0f98
humanhash: earth-red-carbon-mango
File name:mkcxskjd.exe
Download: download sample
Signature Dridex
File size:200'704 bytes
First seen:2020-06-23 13:15:24 UTC
Last seen:2020-06-23 13:50:44 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5f5d7f3d576b5fd54d7374e64458a706 (3 x Dridex)
ssdeep 6144:RQYmU2JFD8euKJ7lfJy7ZcYrDZM8DY8gGTlj:RMU2z8NKJRsrDZM8D5
Threatray 262 similar samples on MalwareBazaar
TLSH 61140119778481B7F79295307D67F5B90A952C734814C66F1F82391CEEBEA2688F032B
Reporter abuse_ch
Tags:Dridex exe


Avatar
abuse_ch
Malspam distributing Dridex:

HELO: ereceivedstoptopvip.xyz
Sending IP: 194.150.214.187
From: Elga Calley <fix@ereceivedstoptopvip.xyz>
Reply-To: nadin.kara@dreammind.com
Subject: Past Due Invoice No. #527023
Attachment: 275247.xlsm

Dridex payload URL:
http://mekund.com/mkcxskjd.exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-06-23 13:17:04 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Dridex

Executable exe d6ddd24040b1f1ae7f42c84ee15f52efa36054e7ed4bb47d177d6b5108c9e5f6

(this sample)

Comments