MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e014812592b1f4a0ff43b95117404149bdcb1dc82924a0f90b7b5ac4699b8dcc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e014812592b1f4a0ff43b95117404149bdcb1dc82924a0f90b7b5ac4699b8dcc
SHA3-384 hash: 67fa8d0123b7d21b36fb655c3ebbd69d05d898eded8aadf963c17be899b29d9d74cf2b2171914d1561301d94d7580f0c
SHA1 hash: 621c3e992ac5c7f944b491d7ca3e4f07b9a20087
MD5 hash: 84048d4a704ca3ed43cf15d44dceeb39
humanhash: coffee-asparagus-winter-high
File name:84048d4a704ca3ed43cf15d44dceeb39.exe
Download: download sample
Signature Dridex
File size:367'104 bytes
First seen:2020-10-28 10:16:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 330220fb172dcaca6b212f108d24896a (1 x Dridex)
ssdeep 6144:OxFHgc/frXtXCye6TDprnbTT2OZM3WUesCBywzlDzOQtEqxzrZCpyB2uvv+:IVg6EyvHtnbTSOZMmZsHyDzOeD8un
TLSH DE74AE9BB11E2516D50C143BCBE8EFDA1D36C5CD06989CB1AB68BCB3A181D4A41C7F1E
Reporter abuse_ch
Tags:Dridex exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-10-28 07:15:00 UTC
AV detection:
22 of 28 (78.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet discovery evasion loader trojan
Behaviour
Suspicious use of WriteProcessMemory
Checks installed software on the system
Checks whether UAC is enabled
Blacklisted process makes network request
Dridex Loader
Dridex
Malware Config
C2 Extraction:
85.207.13.169:443
74.207.242.13:1688
176.58.101.200:49160
164.132.75.129:3388
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

Executable exe e014812592b1f4a0ff43b95117404149bdcb1dc82924a0f90b7b5ac4699b8dcc

(this sample)

Comments