MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d7404b722643050580849f855b65b96a6d499d93be58818c65d7bcb429ecb1bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d7404b722643050580849f855b65b96a6d499d93be58818c65d7bcb429ecb1bd
SHA3-384 hash: 0b5f02305ce2607fd21655a19f67a5dfb8824fe4bfbb92d7fcc0bf69bd2be6df2cc69402a1f2439881a7450c7be8f3ec
SHA1 hash: fce0d759b4b93eda98a964bee8a81d481cf73279
MD5 hash: fb0e8149ac9a94c04ba4536b834858b2
humanhash: snake-whiskey-september-kitten
File name:fb0e8149ac9a94c04ba4536b834858b2.dll
Download: download sample
Signature Dridex
File size:12'288 bytes
First seen:2021-04-22 06:16:55 UTC
Last seen:2021-04-22 07:19:26 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 96:a/mv9FxYXL1GNINGeMwjWcxJFuiZOCCCw8P+1VXZC0d2u0OkuHUIcvBi8gnX2L4E:a/6rMCcxJ7hw821V8+t9KngM4j+iGx1
Threatray 2 similar samples on MalwareBazaar
TLSH 2A426D66F396C1EBCC4A21B31E1F69361A257046539DDC288E00DEDFA3736907C2B552
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 395101 Sample: 20PEFHD8op.dll Startdate: 22/04/2021 Architecture: WINDOWS Score: 52 34 Multi AV Scanner detection for submitted file 2->34 36 Machine Learning detection for sample 2->36 14 loaddll32.exe 1 2->14         started        process3 process4 16 cmd.exe 1 14->16         started        process5 18 rundll32.exe 16->18         started        process6 20 rundll32.exe 18->20         started        process7 22 rundll32.exe 20->22         started        process8 24 rundll32.exe 22->24         started        process9 26 rundll32.exe 24->26         started        process10 28 rundll32.exe 26->28         started        process11 30 rundll32.exe 28->30         started        process12 32 rundll32.exe 30->32         started       
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll d7404b722643050580849f855b65b96a6d499d93be58818c65d7bcb429ecb1bd

(this sample)

  
Delivery method
Distributed via web download

Comments