🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0d923f147d65e191df660c5d593e77599dfe95abf43db404da704012056262b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f0d923f147d65e191df660c5d593e77599dfe95abf43db404da704012056262b
SHA3-384 hash: 1d634a570caefa613dacc17bd9a3402115489fae0a180fdda0905ddac4605e5ebd4b9e119547919bb92b8ae5f6a4b8ee
SHA1 hash: f06aefdefd603a6a5e8c64c2bb52fb6018736c55
MD5 hash: c7e352f3f702bc5a54c13963f2a6e4c0
humanhash: crazy-nevada-montana-mountain
File name:c7e352f3f702bc5a54c13963f2a6e4c0.dll
Download: download sample
Signature Dridex
File size:538'524 bytes
First seen:2021-12-16 08:57:09 UTC
Last seen:2021-12-16 11:18:09 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 6144:1HG2WUYYUeWUkWk+WUCWUmWUOWUwWUA4UUWqqWUGWU8YUCWC4WUiWUrHw9GlzgYg:AOHwszfO5snBpZfk
Threatray 2'742 similar samples on MalwareBazaar
TLSH T182B4BF1E7148C053C9CABD7478B27F2565C5903C2DADA4FBF0A37AA8D74B6A4BC1A074
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
176
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 540842 Sample: AHVcn8Mn1O.dll Startdate: 16/12/2021 Architecture: WINDOWS Score: 56 34 Multi AV Scanner detection for submitted file 2->34 36 Machine Learning detection for sample 2->36 38 Sigma detected: Suspicious Call by Ordinal 2->38 14 loaddll32.exe 1 2->14         started        process3 process4 16 cmd.exe 1 14->16         started        process5 18 rundll32.exe 16->18         started        process6 20 rundll32.exe 18->20         started        process7 22 rundll32.exe 20->22         started        process8 24 rundll32.exe 22->24         started        process9 26 rundll32.exe 24->26         started        process10 28 rundll32.exe 26->28         started        process11 30 rundll32.exe 28->30         started        process12 32 rundll32.exe 30->32         started       
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-12-16 03:23:20 UTC
File Type:
PE (Dll)
AV detection:
12 of 28 (42.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
f0d923f147d65e191df660c5d593e77599dfe95abf43db404da704012056262b
MD5 hash:
c7e352f3f702bc5a54c13963f2a6e4c0
SHA1 hash:
f06aefdefd603a6a5e8c64c2bb52fb6018736c55
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll f0d923f147d65e191df660c5d593e77599dfe95abf43db404da704012056262b

(this sample)

  
Delivery method
Distributed via web download

Comments