🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f045bc5d0dc4890be3163fa236c403dab3d444e92fd5ddc0356dbf3f25f829af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f045bc5d0dc4890be3163fa236c403dab3d444e92fd5ddc0356dbf3f25f829af
SHA3-384 hash: a9ff0ae643c3f9491de5c8fba35095d76563f821ff3ae94ad3c29621c3d62baa7d5a5dabfdd98116f591148c2e70ff9d
SHA1 hash: e222675107a78e19648479a3a994f63fcc58f2a2
MD5 hash: 8c1c54884b90c015330ef19c0cb0a4fc
humanhash: carbon-fifteen-crazy-march
File name:cifvmc5rar
Download: download sample
Signature Dridex
File size:850'432 bytes
First seen:2020-09-30 15:29:29 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 53c075587d0cfda1220f94f113ec2cf4 (1 x Dridex)
ssdeep 24576:ZcZagcfqJvQuFmaYppWG23fpjR+m2DBtTqI3k:uaTfAHYbNSpjR+m2DBtTV3k
Threatray 4 similar samples on MalwareBazaar
TLSH 9C058C04BA939079F0B717BB9E2D51B84939BE944B3094EF63C45BDE96366D18C30B23
Reporter JAMESWT_WT
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2020-09-30 15:27:11 UTC
File Type:
PE (Dll)
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
botnet loader evasion trojan discovery family:dridex
Behaviour
Suspicious use of WriteProcessMemory
Checks installed software on the system
Checks whether UAC is enabled
Blacklisted process makes network request
Dridex Loader
Dridex
Malware Config
C2 Extraction:
146.164.126.197:443
69.16.193.166:9443
193.90.12.122:3098
157.245.103.132:14043
Unpacked files
SH256 hash:
f045bc5d0dc4890be3163fa236c403dab3d444e92fd5ddc0356dbf3f25f829af
MD5 hash:
8c1c54884b90c015330ef19c0cb0a4fc
SHA1 hash:
e222675107a78e19648479a3a994f63fcc58f2a2
SH256 hash:
914e682ec0f6356676e99c8a44285388346aa62ff7ac0f9778353a2b488d4768
MD5 hash:
599a1e38ab115d43188b9462c47e5fba
SHA1 hash:
fb9228c869bde99b3e2d5b1e27efef151ec3513c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll f045bc5d0dc4890be3163fa236c403dab3d444e92fd5ddc0356dbf3f25f829af

(this sample)

Comments