🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e83cff5322e8e8d608328b33c5cc62a31e2370530d80e735ddbc5a477e6579ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: e83cff5322e8e8d608328b33c5cc62a31e2370530d80e735ddbc5a477e6579ec
SHA3-384 hash: 771c7a37636208f1064b78098a2c2d675a465b4a5ac33a5c127430b41e6bf28e5981a256e206b5784c6d749f8f3dedde
SHA1 hash: a08c0a393f772b5631e300203224f637fe58d575
MD5 hash: dcdbb45851110eec62c44ed6a3eedf8b
humanhash: mirror-florida-failed-west
File name:LisectAVT_2403002B_456.dll
Download: download sample
Signature Dridex
File size:192'512 bytes
First seen:2024-07-25 01:27:30 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash e14682cd580b5bc2ebf0ee1ec113cb1f (3 x Dridex)
ssdeep 3072:hA8JmK7ATVfQeVqNFZa/9KzMXJ6jTFDlAwqWut5KZMzfeAAAoto:hzIqATVfQeV2FZalKq6jtGJWuTmd
Threatray 2'596 similar samples on MalwareBazaar
TLSH T11614BF07DF6788A4F9760C754476B237556D4C0E8219EB52CB8EFBB6D03268388B172B
TrID 27.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.3% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Anonymous
Tags:dll Dridex exe


Avatar
Anonymous
this malware sample is very nasty!

Intelligence


File Origin
# of uploads :
1
# of downloads :
441
Origin country :
CN CN
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
dridex lolbin microsoft_visual_cc packed setupapi zusy
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Dridex
Status:
Malicious
First seen:
2021-08-26 05:24:26 UTC
File Type:
PE (Dll)
AV detection:
36 of 38 (94.74%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet discovery loader
Behaviour
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Dridex Loader
Dridex
Malware Config
C2 Extraction:
103.82.248.59:443
54.39.98.141:6602
103.109.247.8:10443
Unpacked files
SH256 hash:
80259e5d421a6929bcb7303d7a325b8b9b8510fb6fd580552eda7fa6d2aec561
MD5 hash:
9904cfcec298267c8a69fd29da091b05
SHA1 hash:
9adaa14bed17652e7433a1e91f4f091ad8d8b459
Detections:
win_dridex_auto
SH256 hash:
206c4e1ce870347200050f50bf5c12328b966bd77c7a82a280afb3279779781d
MD5 hash:
00747b20380d51971cf827c5132f2f3f
SHA1 hash:
f7c5a16643749ae87d2c7ef8369e2a33c38b6984
Detections:
win_doppeldridex_auto
SH256 hash:
e83cff5322e8e8d608328b33c5cc62a31e2370530d80e735ddbc5a477e6579ec
MD5 hash:
dcdbb45851110eec62c44ed6a3eedf8b
SHA1 hash:
a08c0a393f772b5631e300203224f637fe58d575
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Dridex

DLL dll e83cff5322e8e8d608328b33c5cc62a31e2370530d80e735ddbc5a477e6579ec

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::FreeSid
MULTIMEDIA_APICan Play MultimediaWINMM.dll::waveOutGetNumDevs
RAS_APIUses Remote AccessRASAPI32.dll::RasDeleteEntryW
RPC_APICan Execute Remote ProceduresRPCRT4.dll::RpcBindingSetAuthInfoExW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::GetTempPathA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegLoadAppKeyA
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.dll::CreateServiceW

Comments