🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fad0cecec2b7f448148ea2be04e59637b2439580d9c58d2d59c5bd44af33b4dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Dridex


Vendor detections: 10


Intelligence 10 IOCs YARA 6 File information Comments

SHA256 hash: fad0cecec2b7f448148ea2be04e59637b2439580d9c58d2d59c5bd44af33b4dd
SHA3-384 hash: ee21dc11b385722abcd2c3a2081800faa967ac72e169577cfb2ad67ffa0d123c8a200f3378f429f4abb4dbc0d43dfce7
SHA1 hash: 5ca8c80ee1d74e3800a1832c3c68790850262e3f
MD5 hash: 76c9558a0cd42098b2c6e72f2264c1b0
humanhash: twenty-single-hamper-mockingbird
File name:SecuriteInfo.com.Drixed-FJX76C9558A0CD4.8758.9432
Download: download sample
Signature Dridex
File size:786'432 bytes
First seen:2021-11-24 16:48:44 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash d179952d1193e1cd0ba3af2a8e8a650b (2 x Dridex)
ssdeep 12288:x/g8A8wcY0yUcQkQUW0QAa0SSMuCAe2UiaUWQIqGQmy0ymkxceCalbcyZ8fiYBiw:RucRalbcymf1BFr
Threatray 5'464 similar samples on MalwareBazaar
TLSH T117F49F04160C81F2D13EB8F99FEDF291CA3A6F446169D3F8B65662C170C76E5221E78E
Reporter SecuriteInfoCom
Tags:dll Dridex

Intelligence


File Origin
# of uploads :
1
# of downloads :
130
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Dridex unpacked file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 528048 Sample: SecuriteInfo.com.Drixed-FJX... Startdate: 24/11/2021 Architecture: WINDOWS Score: 68 38 64.251.25.156 INFOLINK-MIA-US United States 2->38 40 185.148.168.15 EVERSCALE-ASDE Germany 2->40 42 2 other IPs or domains 2->42 46 Found malware configuration 2->46 48 Multi AV Scanner detection for submitted file 2->48 50 Yara detected Dridex unpacked file 2->50 52 C2 URLs / IPs found in malware configuration 2->52 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        13 cmd.exe 1 9->13         started        15 rundll32.exe 9->15         started        17 5 other processes 9->17 process6 19 WerFault.exe 2 9 11->19         started        22 WerFault.exe 11->22         started        24 rundll32.exe 13->24         started        26 WerFault.exe 9 15->26         started        28 WerFault.exe 15->28         started        30 WerFault.exe 9 17->30         started        32 WerFault.exe 17->32         started        34 WerFault.exe 17->34         started        dnsIp7 44 192.168.2.1 unknown unknown 19->44 36 WerFault.exe 23 9 24->36         started        process8
Threat name:
Win32.Trojan.Drixed
Status:
Malicious
First seen:
2021-11-24 16:49:15 UTC
File Type:
PE (Dll)
AV detection:
19 of 28 (67.86%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dridex botnet:22203 botnet loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Dridex Loader
Dridex
Malware Config
C2 Extraction:
107.170.4.227:443
178.128.222.53:8116
185.148.168.15:4664
64.251.25.156:6602
Unpacked files
SH256 hash:
c0545cd59b3e099866b559d8be1c9d520543f34c5d4093fde48a15789313c4b3
MD5 hash:
03cb6e0a0773420b4b9069bc3dfa77b1
SHA1 hash:
2564e9c69371df31d6f41609670c440a80a4da9e
Detections:
win_doppeldridex_auto
SH256 hash:
87391ed042d021a3b389f3a5ab8adc7739bcf5c6c75c480fd43c5673b6c07a66
MD5 hash:
fd54750f11fedcfb38d83524a611b617
SHA1 hash:
210701f9771063026d9484f3ed7cbb5537d761d8
Detections:
win_dridex_auto
SH256 hash:
fad0cecec2b7f448148ea2be04e59637b2439580d9c58d2d59c5bd44af33b4dd
MD5 hash:
76c9558a0cd42098b2c6e72f2264c1b0
SHA1 hash:
5ca8c80ee1d74e3800a1832c3c68790850262e3f
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DridexLoader
Author:kevoreilly
Description:Dridex v4 dropper C2 parsing function
Rule name:DridexV4
Author:kevoreilly
Description:Dridex v4 Payload
Rule name:dridex_loader
Author:kevoreilly
Description:Dridex Loader
Rule name:MALWARE_Win_DLLLoader
Author:ditekSHen
Description:Detects unknown DLL Loader
Rule name:win_doppeldridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.doppeldridex.
Rule name:win_dridex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.dridex.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Dridex

DLL dll fad0cecec2b7f448148ea2be04e59637b2439580d9c58d2d59c5bd44af33b4dd

(this sample)

  
Delivery method
Distributed via web download

Comments