MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f1ad281c4e5fb172b2a7f7e7346871bac05665e6a9570745d80b2e43e47da1cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Dridex
Vendor detections: 10
| SHA256 hash: | f1ad281c4e5fb172b2a7f7e7346871bac05665e6a9570745d80b2e43e47da1cb |
|---|---|
| SHA3-384 hash: | 0fde85def221ebe08d27a5ca063a2bc8acbe34d1a9b7605cccb68c8d21342ff6878f0e6a80a7851b52a96d905071ab74 |
| SHA1 hash: | 8e73a4a343edf7c70a72e1dca0d131cc9afc82db |
| MD5 hash: | c1cf3ab0002b96f9e91dfc601ca2274a |
| humanhash: | robert-montana-oven-fourteen |
| File name: | c1cf3ab0002b96f9e91dfc601ca2274a |
| Download: | download sample |
| Signature | Dridex |
| File size: | 768'000 bytes |
| First seen: | 2021-10-27 14:46:51 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 25cb031fe02365eafb637dd0a2254650 (34 x Dridex) |
| ssdeep | 12288:EhB6OmN5lx6S3P8UUY9eHTYtI6jd/Tvyis6SX3hwxwXcKjNE3l7w31TwMGjQ/fc:E0LUY9eziI6NT6JtXxwGNCl831TCc/f |
| Threatray | 925 similar samples on MalwareBazaar |
| TLSH | T114F4CF1336EAC079D072157841A0B5E05DCDBE61642E9EEBA390323E863ACD2797D71F |
| Reporter | |
| Tags: | 32 dll Dridex exe |
Intelligence
File Origin
# of uploads :
1
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Detection:
DridexLoader
Result
Verdict:
Malware
Maliciousness:
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
greyware
Malware family:
Dridex
Verdict:
Malicious
Result
Threat name:
Dridex
Detection:
malicious
Classification:
bank.troj.evad
Score:
88 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected Dridex e-Banking trojan
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
Detection:
dridex
Verdict:
malicious
Label(s):
dridex
gozi
Similar samples:
+ 915 additional samples on MalwareBazaar
Result
Malware family:
dridex
Score:
10/10
Tags:
family:dridex botnet:10555 botnet discovery evasion trojan
Behaviour
Suspicious use of WriteProcessMemory
Checks installed software on the system
Checks whether UAC is enabled
Blocklisted process makes network request
Dridex
Malware Config
C2 Extraction:
192.46.210.220:443
143.244.140.214:808
45.77.0.96:6891
185.56.219.47:8116
143.244.140.214:808
45.77.0.96:6891
185.56.219.47:8116
Unpacked files
SH256 hash:
eca6289884408e0cb5184227e6ae0b344e2369c432fc9c5a0c0d747a98a70be3
MD5 hash:
bac19d0e85c08f9a4c0bd771d9311392
SHA1 hash:
e17dc8bed0da54cf685770fe23b0b4b9f33b89e2
SH256 hash:
f1ad281c4e5fb172b2a7f7e7346871bac05665e6a9570745d80b2e43e47da1cb
MD5 hash:
c1cf3ab0002b96f9e91dfc601ca2274a
SHA1 hash:
8e73a4a343edf7c70a72e1dca0d131cc9afc82db
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.url : hxxps://nowreportinglive.com/esg800o7.jpg