🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f03234e69c590e38fb19c15c19a1b1526da18d6ea8d2634ae9fd81dbf5168b2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 11


Maldoc score: 6


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: f03234e69c590e38fb19c15c19a1b1526da18d6ea8d2634ae9fd81dbf5168b2c
SHA3-384 hash: 89e49fdf7defdf881aad413e304168599daeb3822cdd21497830f8cfcf642423bc26bc6d3dbbf4f4c86b5f9ace1bbdf7
SHA1 hash: 425de0627c45d39118b4ab7e15e07fc97df1f31f
MD5 hash: 0b1145386e54c133263fc6e8a9a71ed5
humanhash: twenty-ceiling-london-artist
File name:taxve_554964502_20210816_85994972_572710651.xlsm
Download: download sample
Signature Dridex
File size:239'458 bytes
First seen:2021-08-16 17:18:47 UTC
Last seen:Never
File type:Excel file xlsm
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 3072:SjAeN0RKSwCchO7e/1GrpdXx6sj848QjWvpGtdWWDDEAB7VaQFhIcB6tOVRa1J:SDNSLcq+YXEsWpGj53ha7o+0O
TLSH T10E34011985B3E565E8DB507E4C9E0FDD17B18E2F06D02B42F9E2E64DAD18EE311812C7
Reporter abuse_ch
Tags:22201 Dridex xlsm


Avatar
abuse_ch
Dridex payload URLs:
https://mercedes190portugal.com/old/dI002Nt3U7U5Fm.php
https://cdn.discordapp.com/attachments/876792192524501045/876837913906774076/1.dll

Dridex C2s:
134.209.182.12:443
188.40.100.254:4664
103.109.247.9:10443

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 6
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
Base647_4N180
Base64C_4Q180
Base64G_4R180
Base64K_4S180
Base64O_4T180
Base64S_4U180
Base64W_4V180
Base64__4X180
Base647_5N181
Base64C_5Q181
Base64G_5R181
Base64K_5S181
Base64O_5T181
Base64S_5U181
Base64W_5V181
Base64__5X181
Base647_6N182
Base64C_6Q182
Base64G_6R182
Base64K_6S182
Base64O_6T182
Base64S_6U182
Base64W_6V182
Base64__6X182
Base647_7N183
Base64C_7Q183
Base64G_7R183
Base64K_7S183
Base64O_7T183
Base64S_7U183
Base64W_7V183
Base64__7X183
Base647_8N184
Base64C_8Q184
Base64G_8R184
Base64K_8S184
Base64O_8T184
Base64S_8U184
Base64W_8V184
Base64__8X184
Base647_9N185
Base64C_9Q185
Base64G_9R185
Base64K_9S185
Base64O_9T185
Base64S_9U185
Base64W_9V185
Base64__9X185
Base647_tN190
Base64C_tQ190
Base64G_tR190
Base64K_tS190
Base64O_tT190
Base64S_tU190
Base64W_tV190
Base64__tX190
Base647_uN191
Base64C_uQ191
Base64G_uR191
Base64K_uS191
Base64O_uT191
Base64S_uU191
Base64W_uV191
Base64__uX191
Base647_vN192
Base64C_vQ192
Base64G_vR192
Base64K_vS192
Base64O_vT192
Base64S_vU192
Base64W_vV192
Base64__vX192
Base647_wN193
Base64C_wQ193
Base64G_wR193
Base64K_wS193
Base64O_wT193
Base64S_wU193
Base64W_wV193
Base64__wX193
Base647_xN194
Base64C_xQ194
Base64G_xR194
Base64K_xS194
Base64O_xT194
Base64S_xU194
Base64W_xV194
Base64__xX194
Base647_yN195
Base64C_yQ195
Base64G_yR195
Base64K_yS195
Base64O_yT195
Base64S_yU195
Base64W_yV195
Base64__yX195
Base647_zN196
Base64C_zQ196
Base64G_zR196
Base64K_zS196
Base64O_zT196
Base64S_zU196
Base64W_zV196
Base64__zX196
Base647m4N200
Base64Cm4Q200
Base64Gm4R200
Base64Km4S200
Base64Om4T200
Base64Sm4U200
Base64Wm4V200
Base64_m4X200
Base647m5N201
Base64Cm5Q201
Base64Gm5R201
Base64Km5S201
Base64Om5T201
Base64Sm5U201
Base64Wm5V201
Base64_m5X201
Base647m6N202
Base64Cm6Q202
Base64Gm6R202
Base64Km6S202
Base64Om6T202
Base64Sm6U202
Base64Wm6V202
Base64_m6X202
Base647m7N203
Base64Cm7Q203
Base64Gm7R203
Base64Km7S203
Base64Om7T203
Base64Sm7U203
Base64Wm7V203
Base64_m7X203
Base647m8N204
Base64Cm8Q204
Base64Gm8R204
Base64Km8S204
Base64Om8T204
Base64Sm8U204
Base64Wm8V204
Base64_m8X204
Base647m9N205
Base64Cm9Q205
Base64Gm9R205
Base64Km9S205
Base64Om9T205
Base64Sm9U205
Base64Wm9V205
Base64_m9X205
Base647mtN210
Base64CmtQ210
Base64GmtR210
Base64KmtS210
Base64OmtT210
Base64SmtU210
Base64WmtV210
Base64_mtX210
Base647muN211
Base64CmuQ211
Base64GmuR211
Base64KmuS211
Base64OmuT211
Base64SmuU211
Base64WmuV211
Base64_muX211
Base647mvN212
Base64CmvQ212
Base64GmvR212
Base64KmvS212
Base64OmvT212
Base64SmvU212
Base64WmvV212
Base64_mvX212
Base647mwN213
Base64CmwQ213
Base64GmwR213
Base64KmwS213
Base64OmwT213
Base64SmwU213
Base64WmwV213
Base64_mwX213
Base647mxN214
Base64CmxQ214
Base64GmxR214
Base64KmxS214
Base64OmxT214
Base64SmxU214
Base64WmxV214
Base64_mxX214
Base647myN215
Base64CmyQ215
Base64GmyR215
Base64KmyS215
Base64OmyT215
Base64SmyU215
Base64WmyV215
Base64_myX215
Base647mzN216
Base64CmzQ216
Base64GmzR216
Base64KmzS216
Base64OmzT216
Base64SmzU216
Base64WmzV216
Base64_mzX216
Base647n4N240
Base64Cn4Q240
Base64Gn4R240
Base64Kn4S240
Base64On4T240
Base64Sn4U240
Base64Wn4V240
Base64_n4X240
Base647n5N241
Base64Cn5Q241
Base64Gn5R241
Base64Kn5S241
Base64On5T241
Base64Sn5U241
Base64Wn5V241
Base64_n5X241
Base647n6N242
Base64Cn6Q242
Base64Gn6R242
Base64Kn6S242
Base64On6T242
Base64Sn6U242
Base64Wn6V242
Base64_n6X242
Base647n7N243
Base64Cn7Q243
Base64Gn7R243
Base64Kn7S243
Base64On7T243
Base64Sn7U243
Base64Wn7V243
Base64_n7X243
Base647n8N244
Base64Cn8Q244
Base64Gn8R244
Base64Kn8S244
Base64On8T244
Base64Sn8U244
Base64Wn8V244
Base64_n8X244
Base647n9N245
Base64Cn9Q245
Base64Gn9R245
Base64Kn9S245
Base64On9T245
Base64Sn9U245
Base64Wn9V245
Base64_n9X245
Base647ntN250
Base64CntQ250
Base64GntR250
Base64KntS250
Base64OntT250
Base64SntU250
Base64WntV250
Base64_ntX250
Base647nuN251
Base64CnuQ251
Base64GnuR251
Base64KnuS251
Base64OnuT251
Base64SnuU251
Base64WnuV251
Base64_nuX251
Base647nvN252
Base64CnvQ252
Base64GnvR252
Base64KnvS252
Base64OnvT252
Base64SnvU252
Base64WnvV252
Base64_nvX252
Base647nwN253
Base64CnwQ253
Base64GnwR253
Base64KnwS253
Base64OnwT253
Base64SnwU253
Base64WnwV253
Base64_nwX253
Base647nxN254
Base64CnxQ254
Base64GnxR254
Base64KnxS254
Base64OnxT254
Base64SnxU254
Base64WnxV254
Base64_nxX254
Base647nyN255
Base64CnyQ255
Base64GnyR255
Base64KnyS255
Base64OnyT255
Base64SnyU255
Base64WnyV255
Base64_nyX255
Base647nzN256
Base64CnzQ256
Base64GnzR256
Base64KnzS256
Base64OnzT256
Base64SnzU256
Base64WnzV256
Base64_nzX256
Base647o4N280
Base64Co4Q280
Base64Go4R280
Base64Ko4S280
Base64Oo4T280
Base64So4U280
Base64Wo4V280
Base64_o4X280
Base647o5N281
Base64Co5Q281
Base64Go5R281
Base64Ko5S281
Base64Oo5T281
Base64So5U281
Base64Wo5V281
Base64_o5X281
Base647o6N282
Base64Co6Q282
Base64Go6R282
Base64Ko6S282
Base64Oo6T282
Base64So6U282
Base64Wo6V282
Base64_o6X282
Base647o7N283
Base64Co7Q283
Base64Go7R283
Base64Ko7S283
Base64Oo7T283
Base64So7U283
Base64Wo7V283
Base64_o7X283
Base647o8N284
Base64Co8Q284
Base64Go8R284
Base64Ko8S284
Base64Oo8T284
Base64So8U284
Base64Wo8V284
Base64_o8X284
Base647o9N285
Base64Co9Q285
Base64Go9R285
Base64Ko9S285
Base64Oo9T285
Base64So9U285
Base64Wo9V285
Base64_o9X285
Base647otN290
Base64CotQ290
Base64GotR290
Base64KotS290
Base64OotT290
Base64SotU290
Base64WotV290
Base64_otX290
Base647ouN291
Base64CouQ291
Base64GouR291
Base64KouS291
Base64OouT291
Base64SouU291
Base64WouV291
Base64_ouX291
Base647ovN292
Base64CovQ292
Base64GovR292
Base64KovS292
Base64OovT292
Base64SovU292
Base64WovV292
Base64_ovX292
Base647owN293
Base64CowQ293
Base64GowR293
Base64KowS293
Base64OowT293
Base64SowU293
Base64WowV293
Base64_owX293
Base647oxN294
Base64CoxQ294
Base64GoxR294
Base64KoxS294
Base64OoxT294
Base64SoxU294
Base64WoxV294
Base64_oxX294
Base647oyN295
Base64CoyQ295
Base64GoyR295
Base64KoyS295
Base64OoyT295
Base64SoyU295
Base64WoyV295
Base64_oyX295
Base647ozN296
Base64CozQ296
Base64GozR296
Base64KozS296
Base64OozT296
Base64SozU296
Base64WozV296
Base64_ozX296
SuspiciousEXECMay run an executable file or a system
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousXLM macrosheetXLM macrosheet found. It could contain malicious code

Intelligence


File Origin
# of uploads :
1
# of downloads :
192
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
taxve_554964502_20210816_85994972_572710651.xlsm
Verdict:
Malicious activity
Analysis date:
2021-08-16 17:21:31 UTC
Tags:
macros40

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/vnd.ms-excel.sheet.macroEnabled.12
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file
Creating a process with a hidden window
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Sending a UDP request
Launching a process by exploiting the app vulnerability
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Excel4Macro
Document image
Document image
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl
Score:
60 / 100
Signature
Document exploit detected (creates forbidden files)
Document exploit detected (process start blacklist hit)
Microsoft Office creates scripting files
Sigma detected: Microsoft Office Product Spawning Windows Shell
Behaviour
Behavior Graph:
Threat name:
Script.Trojan.IcedID
Status:
Malicious
First seen:
2021-08-16 17:19:06 UTC
AV detection:
4 of 46 (8.70%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22201 botnet evasion loader macro trojan xlm
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies system certificate store
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks whether UAC is enabled
Loads dropped DLL
Blocklisted process makes network request
Downloads MZ/PE file
Dridex Loader
Dridex
Process spawned unexpected child process
Malware Config
C2 Extraction:
134.209.182.12:443
188.40.100.254:4664
103.109.247.9:10443
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Microsoft_XLSX_with_Macrosheet
Rule name:Microsoft_XLSX_with_Macrosheet

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Dridex

Excel file xlsm f03234e69c590e38fb19c15c19a1b1526da18d6ea8d2634ae9fd81dbf5168b2c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments