MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 daf2420261ff0c9cbc0e4026c64257aa18069e93067bfc1fdfbbd4d5b14157b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: daf2420261ff0c9cbc0e4026c64257aa18069e93067bfc1fdfbbd4d5b14157b4
SHA3-384 hash: 530ad49d876a0e04f966cd90fe8370fb738886ca517c55832d23bbdf4859565b5615180a03c5483ba90ebf26b9c5a5ca
SHA1 hash: 24b014dc584c35ca21e2ab4054ceb6bf5b417c1a
MD5 hash: 675450554cfda694ade9578587cab85e
humanhash: iowa-pasta-mississippi-lamp
File name:675450554cfda694ade9578587cab85e.dll
Download: download sample
Signature Dridex
File size:81'920 bytes
First seen:2020-12-27 07:39:56 UTC
Last seen:2020-12-27 09:36:12 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 96:YTuKPpQeS1EM8SScBUjIgtYdl0zQWTAlUzw2TgmzQ8G7jnxIAfPfPHu/yLbHHH9G:3gCS+UsA8WMUc2H8nxRfP2yLrnWzUCP
Threatray 29 similar samples on MalwareBazaar
TLSH E983BF9489454196D0AAE0F3190F246B72FC09CF1B350272A9715F2F57FB4BD2E8B4AE
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
354
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 334221 Sample: 3cPAo4nalK.dll Startdate: 27/12/2020 Architecture: WINDOWS Score: 23 10 Machine Learning detection for sample 2->10 6 loaddll32.exe 1 2->6         started        process3 process4 8 WerFault.exe 3 9 6->8         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2020-12-27 07:40:06 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
daf2420261ff0c9cbc0e4026c64257aa18069e93067bfc1fdfbbd4d5b14157b4
MD5 hash:
675450554cfda694ade9578587cab85e
SHA1 hash:
24b014dc584c35ca21e2ab4054ceb6bf5b417c1a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll daf2420261ff0c9cbc0e4026c64257aa18069e93067bfc1fdfbbd4d5b14157b4

(this sample)

  
Delivery method
Distributed via web download

Comments