🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dda4598f29a033d2ec4f89f4ae687e12b927272462d25ca1b8dec4dc0acb1bec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: dda4598f29a033d2ec4f89f4ae687e12b927272462d25ca1b8dec4dc0acb1bec
SHA3-384 hash: d437f7a3b7f0ef1174db810ba8567ab7661ec34b3707a044582836c87ed4c498c528f7c1d52bc66b8e5c34aca3cb64de
SHA1 hash: 8631dc198c7641300b08d17fa8686095f045821a
MD5 hash: 3eed5f9a1d57b6ae71a5d434ea38814d
humanhash: sink-lactose-spaghetti-fix
File name:dda4598f29a033d2ec4f89f4ae687e12b927272462d25ca1b8dec4dc0acb1bec.bin
Download: download sample
Signature Dridex
File size:222'720 bytes
First seen:2021-12-24 19:05:26 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 7f6080ebd99c0fc2532c598f3501f73e (1 x Dridex)
ssdeep 6144:hSw1l58PKY6gorM51zPIX116hYkQUIsiihS:91l5qxXlPIX/4YndX
Threatray 5'732 similar samples on MalwareBazaar
TLSH T18424E08ADFE783F0E1C6683E00833C6B505AA451C1ADD9BECBC5FAD1E547D82266215F
Reporter Arkbird_SOLG
Tags:dll Dridex Grief Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
845
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 545043 Sample: Msy1iPjhmT.bin Startdate: 24/12/2021 Architecture: WINDOWS Score: 64 22 Antivirus / Scanner detection for submitted sample 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Machine Learning detection for sample 2->26 28 Sigma detected: Suspicious Call by Ordinal 2->28 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 WerFault.exe 2 9 8->14         started        process5 16 rundll32.exe 10->16         started        18 WerFault.exe 9 12->18         started        process6 20 WerFault.exe 23 9 16->20         started       
Threat name:
Win32.Ransomware.DoppelPaymer
Status:
Malicious
First seen:
2021-06-24 01:05:33 UTC
File Type:
PE (Dll)
AV detection:
25 of 28 (89.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
15442331fe9156d1f66ca9d7d54ccb001e6ef9a81678bad2aaeaa463596be198
MD5 hash:
e03064ca663daf9f213d750230135ef3
SHA1 hash:
b363cbdf394c98ca1f7ea818e5dfd0281146cbff
Detections:
win_dridex_auto
SH256 hash:
b48640f9ad3e0e1f5c326cbbff017a1329e5350ec4a56cb0bdd1e284fe848d60
MD5 hash:
81deac04d1f9b7a232cbe927a17845c7
SHA1 hash:
3131d4ca2a7eba8af9f970f6b6268a2bec13f749
Detections:
win_doppelpaymer_auto
SH256 hash:
dda4598f29a033d2ec4f89f4ae687e12b927272462d25ca1b8dec4dc0acb1bec
MD5 hash:
3eed5f9a1d57b6ae71a5d434ea38814d
SHA1 hash:
8631dc198c7641300b08d17fa8686095f045821a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:win_doppelpaymer_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppelpaymer.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments