🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f914a4322fcdfa71c35341e1e8614a14ab25ee83e3f7ed4932976ef97142bd5c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: f914a4322fcdfa71c35341e1e8614a14ab25ee83e3f7ed4932976ef97142bd5c
SHA3-384 hash: 4a6a74daaa230155d6df4b83e1a0a24050af6cf0f7fbea4b8a974a721f5d2937b4f939f1237b029dcc0169e062cd30cd
SHA1 hash: 406c1bcacdee67e02b743afbd593f6d3607ec96d
MD5 hash: 1ae2da441d713c8833643dc9cb81960f
humanhash: batman-uniform-georgia-timing
File name:PvpAJpKOFJDniggerfuckburnjew.nigga.dll
Download: download sample
Signature Dridex
File size:786'432 bytes
First seen:2021-11-29 14:46:48 UTC
Last seen:2021-11-29 14:56:48 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash e2b132d0c5b12e3a8c3c997404d70860 (3 x Dridex)
ssdeep 12288:HNJHbhN75iggE/YdWwdGmdaidYmdIcdWun84dU6dWMdC+duo1skdm0JWs7WGvWKw:tjigqttbZrtdlJPL/bVpDFnnd7
Threatray 5'468 similar samples on MalwareBazaar
TLSH T158F4AE8207179423EB9E97388A4F7644F51702D8885C6ED27EFDDDB780E98D93421F2A
Reporter JAMESWT_WT
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
2
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 530436 Sample: PvpAJpKOFJDniggerfuckburnje... Startdate: 29/11/2021 Architecture: WINDOWS Score: 68 38 23.253.208.162 RACKSPACEUS United States 2->38 40 51.68.138.110 OVHFR France 2->40 42 2 other IPs or domains 2->42 44 Found malware configuration 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected Dridex unpacked file 2->48 50 C2 URLs / IPs found in malware configuration 2->50 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 cmd.exe 1 9->11         started        13 rundll32.exe 9->13         started        15 rundll32.exe 9->15         started        17 4 other processes 9->17 process6 19 rundll32.exe 11->19         started        21 WerFault.exe 13->21         started        23 WerFault.exe 13->23         started        25 WerFault.exe 9 15->25         started        27 WerFault.exe 9 17->27         started        29 WerFault.exe 9 17->29         started        31 WerFault.exe 9 17->31         started        process7 33 WerFault.exe 23 9 19->33         started        dnsIp8 36 192.168.2.1 unknown unknown 33->36
Threat name:
Win32.Infostealer.Dridex
Status:
Malicious
First seen:
2021-11-29 14:47:14 UTC
File Type:
PE (Dll)
AV detection:
22 of 27 (81.48%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22203 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
51.68.138.110:443
206.189.150.190:8116
103.109.247.10:10443
23.253.208.162:9217
Unpacked files
SH256 hash:
26b3ef9296a8c90321430dee094976f2fcda4d3c0866ac6c6d53fad71ebe5148
MD5 hash:
9ab9e27ffab883869ab20d9fa37896e7
SHA1 hash:
b5b542d16e0a9f063ce85df615d16a2edb889b54
Detections:
win_doppeldridex_auto
SH256 hash:
d7d12b6d9f0555ff76bc0e59882dd63702263df04b93ebce7a3fa52d61d51fe3
MD5 hash:
c569826f9524e265e01e6a4780bfefcf
SHA1 hash:
998fd19cbaabb9a39fc731a27825fb593cc2bec9
Detections:
win_dridex_auto
SH256 hash:
f914a4322fcdfa71c35341e1e8614a14ab25ee83e3f7ed4932976ef97142bd5c
MD5 hash:
1ae2da441d713c8833643dc9cb81960f
SHA1 hash:
406c1bcacdee67e02b743afbd593f6d3607ec96d
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll f914a4322fcdfa71c35341e1e8614a14ab25ee83e3f7ed4932976ef97142bd5c

(this sample)

  
Delivery method
Distributed via web download

Comments