🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eaad21aef7fe38729c1c7fafe375e2c9e8f12102d75e7eee7a0b1725b68939f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Intelligence 11 IOCs YARA 8 File information Comments

SHA256 hash: eaad21aef7fe38729c1c7fafe375e2c9e8f12102d75e7eee7a0b1725b68939f4
SHA3-384 hash: 39a98b74c9d59c424fde87bf4b72ccbebf50b3f69bcf992f1af3755d4153f0689e4498cf20ba3aebb3007df15290cd48
SHA1 hash: c058aae1168ee2af5ea7a903d3fa01982a467be5
MD5 hash: a81cf9c91b5fbd133a9695e9eb0ec219
humanhash: minnesota-victor-cat-pluto
File name:SecuriteInfo.com.Trojan.Dridex.777.28766.21785
Download: download sample
Signature Dridex
File size:668'520 bytes
First seen:2021-11-18 00:00:03 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 43b460ede91c0828a2b4acde6b98d16d (26 x Dridex)
ssdeep 12288:D9we+YtfLwxfZYnfh0xnf2xfH6xfpaEdk9qcK05GDdiO2cGoOUwg9Z:D9we+YtfufkfonsfYfpuN5GxiO2cGoOc
Threatray 5'362 similar samples on MalwareBazaar
TLSH T100E49D067CF9989CD511ABBD421E86FB8BB089B784D0CAC1C1199F3A5C17BDBE54C62C
Reporter SecuriteInfoCom
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
163
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
67%
Tags:
dridex overlay packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 524110 Sample: SecuriteInfo.com.Trojan.Dri... Startdate: 18/11/2021 Architecture: WINDOWS Score: 68 17 54.37.70.105 OVHFR France 2->17 19 142.93.218.86 DIGITALOCEAN-ASNUS United States 2->19 21 2 other IPs or domains 2->21 23 Found malware configuration 2->23 25 Multi AV Scanner detection for submitted file 2->25 27 Yara detected Dridex unpacked file 2->27 29 C2 URLs / IPs found in malware configuration 2->29 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        process6 13 rundll32.exe 11->13         started        process7 15 WerFault.exe 23 9 13->15         started       
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-17 23:33:43 UTC
AV detection:
12 of 27 (44.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Suspicious use of NtCreateProcessExOtherParentProcess
Malware Config
C2 Extraction:
54.37.70.105:443
198.199.70.22:6602
164.68.99.3:5007
142.93.218.86:4664
Unpacked files
SH256 hash:
952ff578426c1a5099453ee4fe5115324ce190b74cd2968d966616f96e90cd0c
MD5 hash:
9bc7f2957d0196ca148648814e4b51a1
SHA1 hash:
0375804daf0d0ed4dab8f52fc4369c17effa132e
Detections:
win_dridex_auto
Parent samples :
24aa64643c101064bade7ca8cd217496cfc1da80fde9376b9d32518810d30f3f
468a4aa5a13ab132c1c508471457f549f8d142297c5f32ab2e7afe4fb792a017
f0762f10c16f8218df35c41dc568232b0bc9e353d5d6aa83fdc3f38c93af4e60
9417c39209cd840dfd4884436ba31e6469f75afc8a1bd97764e6e98711e6e417
20b06638864a86b2c163b0ebf64a614210c6636388b0a0e22a5e3d21b8d7dfd8
3f6d92c7bee864a8fe706238eb77ff21b6e549119dbbea0f2406acfdeba93a64
217b87e638e156fee977e260958b60efd132c2365a3b162cdf937510998470ac
a405a8d47777f4c46cff38974ea4d3812a59f3c300497ed0eaa29cfda48a7d13
4c90c171975196606af9c94d080b97adce16028cf68492a36eea90247c646212
cd2aedfa1d7113c4aa22764886c0918455e77408db27b0350c91ffdf61bb213d
93010d7ad9febba08228a9c0da459cd4d0fe199c6766b0d005239b30740d7ceb
ba795bea08ef0fd57f6801379f34d2a765ed0adab94a70c517ee45cfa9004af6
4f165e1231ca11a4d0c1dac2d56acbbcd3dbcd3ad35b194f2086f3292a0e1ecb
38fb126b6db4391085543111f87b8a739411cecfc1b185efde86b7edb8f1d186
eda1d1d03c1674e42db93313ddbef8d970aa8404b6aec8bf9714548f4a617564
9ed698e57550932b90d2c591fa199e62694b2d0a9d99f01f645732bc732b8afa
a124c781beff018c039d54c6820d0b28ef62b0305412ce6bf079fa5ee12595e1
8bde4fd15203de4aa8e74ceda8697a1fa7f76a380f27f76553d61be3dea75d90
eaad21aef7fe38729c1c7fafe375e2c9e8f12102d75e7eee7a0b1725b68939f4
f0515a37906e1659cb29e217a9a9eaae5ebb5f79c9575c18c8388c8eb202fdf2
0a67e8370883a0c86dc3d6dd9a8798fc2d46ed3e863e0a1a5ce55853becf6143
39b7a98df99d10c45344b5380e9521a8450630800b66164fe376f384c32d1375
f7b46e3c2f71ca5e0e93e90ed06f667b1f0b308f723a96d736f0f6d9534e2d7c
e98088458287ae8b9dde8e19695a3b1abce06ab21c0de10ed87e29a54ddf760b
7b0bd3060b2ac4d062b8b218fd68c357ebe716a7f51af5687d338d93a51f5c9d
eb41431176cb116acd2bd2c52d46c1f1bdd0ec430293b915238c0d5696cdd12f
SH256 hash:
3f93bffdbf343b8771c8822c464e50c22ff3a2de242c21c1ab01943b659c18cf
MD5 hash:
0bf4f1149c4f72bb97321b1fa41f179f
SHA1 hash:
1c46b6d5e6a72a27f7515ac40286f0f365ad9e7f
Detections:
win_doppeldridex_auto
SH256 hash:
eaad21aef7fe38729c1c7fafe375e2c9e8f12102d75e7eee7a0b1725b68939f4
MD5 hash:
a81cf9c91b5fbd133a9695e9eb0ec219
SHA1 hash:
c058aae1168ee2af5ea7a903d3fa01982a467be5
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:dridex_loader
Author:kevoreilly
Description:Dridex Loader
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:Sectigo_Code_Signed
Description:Detects code signed by the Sectigo RSA Code Signing CA
Reference:https://bazaar.abuse.ch/export/csv/cscb/
Rule name:Sectigo_Code_Signed
Description:Detects code signed by the Sectigo RSA Code Signing CA
Reference:https://bazaar.abuse.ch/export/csv/cscb/
Rule name:win_doppeldridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppeldridex.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll eaad21aef7fe38729c1c7fafe375e2c9e8f12102d75e7eee7a0b1725b68939f4

(this sample)

  
Delivery method
Distributed via web download

Comments