🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efbd76616dc1cd8210a8c54611f4ffa88e635f0f6ded2f8ff48311737635edda. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 13


Intelligence 13 IOCs YARA File information Comments

SHA256 hash: efbd76616dc1cd8210a8c54611f4ffa88e635f0f6ded2f8ff48311737635edda
SHA3-384 hash: 90a12d36ee8563057b08c51b8f80d51f12a09b42a38e7108c4ba721af09b1d26a6e9d8ce8bc4922419d7c87f0f1f4a1b
SHA1 hash: 222cf86c3b59f466292bb734be308cda77c3ddff
MD5 hash: 63c22ce32346e029fa5a1ec1ae619d0f
humanhash: oranges-michigan-nitrogen-idaho
File name:63c22ce32346e029fa5a1ec1ae619d0f.dll
Download: download sample
Signature Dridex
File size:565'248 bytes
First seen:2021-12-24 08:10:20 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 7119acbff3b38a52756367cf5bfb78f2 (3 x Dridex)
ssdeep 12288:jGBK1zWlDqhPUVpqF9q9FAfPWvF+r3qTFCX1za7EV8RgfQOOvDC93:jNkIu2KAGIOwZ+v
Threatray 5'764 similar samples on MalwareBazaar
TLSH T160C49F12D6402DCBE76EB9BBCA773309A7D21C20C13254F635365165E6E0ACDAEDBB10
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
736
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
76 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Tries to delay execution (extensive OutputDebugStringW loop)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 544850 Sample: Pv3ZsGsdfS.dll Startdate: 24/12/2021 Architecture: WINDOWS Score: 76 18 185.4.135.27 TOPHOSTGR Greece 2->18 20 85.10.248.28 HETZNER-ASDE Germany 2->20 22 2 other IPs or domains 2->22 24 Found malware configuration 2->24 26 Multi AV Scanner detection for submitted file 2->26 28 Yara detected Dridex unpacked file 2->28 30 2 other signatures 2->30 9 loaddll32.exe 1 2->9         started        signatures3 process4 signatures5 32 Tries to delay execution (extensive OutputDebugStringW loop) 9->32 12 cmd.exe 1 9->12         started        process6 process7 14 rundll32.exe 12->14         started        process8 16 WerFault.exe 23 9 14->16         started       
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-12-24 02:02:20 UTC
File Type:
PE (Dll)
AV detection:
24 of 28 (85.71%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
144.91.122.102:443
85.10.248.28:593
185.4.135.27:5228
80.211.3.13:8116
Unpacked files
SH256 hash:
b7718ede382fafe5da73a43e809391da15ae04099ae1c2f1e0ef42daa6b65fd4
MD5 hash:
15110f4f9e955e115d1e4b22978550e6
SHA1 hash:
e5ecc27a4d131811f0a9c8e4bf752a8e7000aa5f
Detections:
win_doppeldridex_auto
SH256 hash:
79f1069ec1ce229b4bece9d61821a28c0a11b918a7f4cb89d99c2c7580bc464d
MD5 hash:
a43e5db64a8ba6e58986577637a9d28d
SHA1 hash:
1c3b788598c3f23a212d089983267f1afdd41917
Detections:
win_dridex_auto
SH256 hash:
efbd76616dc1cd8210a8c54611f4ffa88e635f0f6ded2f8ff48311737635edda
MD5 hash:
63c22ce32346e029fa5a1ec1ae619d0f
SHA1 hash:
222cf86c3b59f466292bb734be308cda77c3ddff
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll efbd76616dc1cd8210a8c54611f4ffa88e635f0f6ded2f8ff48311737635edda

(this sample)

  
Delivery method
Distributed via web download

Comments