MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f872d801ef2e4a51b1e307ce4de418a94bb64c917f8969af7e1822d71751836f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f872d801ef2e4a51b1e307ce4de418a94bb64c917f8969af7e1822d71751836f
SHA3-384 hash: 8ef4718c4d70e7d4b278502753eda4e8ecdbdaae77a468a09e7ff822921d1f6e744f9cbd2abdeb005ee4c3083b512075
SHA1 hash: 79e6c4795c59a10616bdfbc4c8d99c92838eb379
MD5 hash: c3b21057f1c7d7d8752be2c792dfc661
humanhash: michigan-march-bacon-echo
File name:f872d801ef2e4a51b1e307ce4de418a94bb64c917f8969af7e1822d71751836f
Download: download sample
Signature Dridex
File size:377'645 bytes
First seen:2020-11-06 00:40:13 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash f973b752dc5ac349369486fc7f90c6b1 (3 x Dridex, 1 x ZLoader)
ssdeep 6144:S3s9vfpA09TUZiYWpcl8Yte2YMnnWZI8VQ3SSOED1nUmhMwHpId7XGDT:Sc9vDhUZiYWpcl80YMnv3YERntMwHpqA
TLSH 24844B06FBC40E77C9CB217AC45991774277EEA507A5FA0357B9B948DAF13E43B20A02
Reporter seifreed
Tags:Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Threat name:
Win32.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-11-01 14:02:22 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments