🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f35009a6d37e4bb19704ecc3ed24293ec177b80479e6324881d49c795cfdb1c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: f35009a6d37e4bb19704ecc3ed24293ec177b80479e6324881d49c795cfdb1c7
SHA3-384 hash: 680b2e516bea5240e6eb7bb4b91ee189dd919867d91e4194f3055afbca680ff84d379b22b27be1ce8163a0e7b90c7378
SHA1 hash: 155416a6c7971090d61d105e1ef7b465987b3f2a
MD5 hash: a799bb8393a65fb3482b388f71c5bc32
humanhash: hawaii-illinois-violet-island
File name:a799bb8393a65fb3482b388f71c5bc32.dll
Download: download sample
Signature Dridex
File size:159'744 bytes
First seen:2021-04-19 18:52:04 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash f71b9cb9891e9cf4bae79d2b5aa115c6 (1'586 x Dridex)
ssdeep 3072:HiFieJeVDC5PIh/31VeSDH2jW+zsKWncDlRe0PLI:ceAU/TeSH26cs+7s
TLSH 1FF3E10AED9FEA88E85C51F1CA4C363EE9713E371B5BDD08C584AE9DC24F25694B0352
Reporter abuse_ch
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Gathering data
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 392755 Sample: qQITXkfLyS.dll Startdate: 19/04/2021 Architecture: WINDOWS Score: 23 34 Machine Learning detection for sample 2->34 14 loaddll32.exe 1 2->14         started        process3 process4 16 cmd.exe 1 14->16         started        process5 18 rundll32.exe 16->18         started        process6 20 rundll32.exe 18->20         started        process7 22 rundll32.exe 20->22         started        process8 24 rundll32.exe 22->24         started        process9 26 rundll32.exe 24->26         started        process10 28 rundll32.exe 26->28         started        process11 30 rundll32.exe 28->30         started        process12 32 rundll32.exe 30->32         started       
Gathering data
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll f35009a6d37e4bb19704ecc3ed24293ec177b80479e6324881d49c795cfdb1c7

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-04-19 19:01:37 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [B0009.029] Anti-Behavioral Analysis::Instruction Testing
1) [B0012.001] Anti-Static Analysis::Argument Obfuscation
2) [C0026.002] Data Micro-objective::XOR::Encode Data