MALICIOUS — bf223fd17317da1765b646da36a30f1e7c20c48198e51e9c3594c872c495aa37
MALICIOUS — bf223fd17317da1765b646da36a30f1e7c20c48198e51e9c3594c872c495aa37 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Dridex family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
bf223fd17317da1765b646da36a30f1e7c20c48198e51e9c3594c872c495aa37 - SHA-1:
f95dc3837d728b933d2c2d3cb3b0aa8c976a43c4 - MD5:
19c1242864ef506156d434130aed7cf8 - imphash:
00dc80a4e597bee8c7ee3e2c1d4a9cde - ssdeep:
12288:Qfgv3KYnXlX4qdIrZBjDzZTph8a8/deXddu:l3KYnXlX4q6P172M3u - TLSH:
T14553D1E9A7314632FEC999206336905C6933EEE340F5DBDC89959CD9A3CA1F720A5034 - Submitted as: bf223fd17317da1765b646da36a30f1e7c20c48198e51e9c3594c872c495aa37
- File type: pe · Size: 1024000 bytes
- Verdict: malicious (98/100) · Family: Dridex
Detections (4 of 56 engines)
- ClamAV (daily): Win.Dropper.Dridex-10027551-0
- Microsoft Defender: Trojan:Win64/Dridex.QM!MTB
- Trellix Stinger (McAfee): Drixed-FJX!19C1242864EF
- Kaspersky (KVRT): HEUR:Trojan.Win64.Injexa.pef
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Dridex-10027551-0 (rule
Win.Dropper.Dridex-10027551-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win64/Dridex.QM!MTB (rule
Trojan:Win64/Dridex.QM!MTB) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Drixed-FJX!19C1242864EF (rule
Drixed-FJX!19C1242864EF) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win64.Injexa.pef (rule
HEUR:Trojan.Win64.Injexa.pef) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
70365 behavior events · 2 ATT&CK techniques · 18 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db -
bf10e54e7d5494e7dd941cc33c8b2feb4f815c37d2e7e8bc88c5b3d9ae06a65d - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db -
f5a3659da44597f82d00b4b480bb44daf1e904893bd986e10fac889a34e4053c - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db -
52cde4f354b8eab4976ceba25b58cbd7efcdf7ccc3871bfe9d9d040850e84d33 - C:\Users\analyst\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db -
257c6f1e02704862bd9bf2a05704086d5779d22f90fccdfeeaeb1ae1cb81cb7a - bbd9e05e70ec8cffd9569405c9fe6a8003717914b77b22ae5aa650fede67c0af -
bbd9e05e70ec8cffd9569405c9fe6a8003717914b77b22ae5aa650fede67c0af - b2cef4caad67e88d5e55b70e7e42b974055c22d4ec97492152047165b909b12e -
b2cef4caad67e88d5e55b70e7e42b974055c22d4ec97492152047165b909b12e - 6c8eb4e21b245bf3c08cd02df86b4f1516a376aa5503cae053ebee855b73203c -
6c8eb4e21b245bf3c08cd02df86b4f1516a376aa5503cae053ebee855b73203c - 34b2e4fc9a56fc631b88c28bd9559c02698fbb7f125c55c2d122bb119bf6d325 -
34b2e4fc9a56fc631b88c28bd9559c02698fbb7f125c55c2d122bb119bf6d325 - 62375771444e16f9b2b889ca44474a6af2ae4fa3f15ccd8b1d016ee29beb50f4 -
62375771444e16f9b2b889ca44474a6af2ae4fa3f15ccd8b1d016ee29beb50f4 - b83d08ed71d57894f918a337381d03e524cc8a6327963a392880729b51cf20d7 -
b83d08ed71d57894f918a337381d03e524cc8a6327963a392880729b51cf20d7 - e387636a6c21f6c145fc62e599c26ed3fc9e30c548ac0a83df954e7fd0f3ec0b -
e387636a6c21f6c145fc62e599c26ed3fc9e30c548ac0a83df954e7fd0f3ec0b - d70e7169cd1c8a338aa9d169545cc9b04bb259f35b3c31f7162ecbfd772c27ec -
d70e7169cd1c8a338aa9d169545cc9b04bb259f35b3c31f7162ecbfd772c27ec - 14552f3bef42907d22f1586b4a306b8c7d00c5113321e61a1a800758e083b32f -
14552f3bef42907d22f1586b4a306b8c7d00c5113321e61a1a800758e083b32f - 53a2ee8ba885bbea63e23853bc83cd550db53a6d5f1756aae40811b962749d10 -
53a2ee8ba885bbea63e23853bc83cd550db53a6d5f1756aae40811b962749d10 - 87b5fe7e7b067aed3c9387a5ac3d701e3698a7bcb7fd5c2dd4bba3a50d199d6a -
87b5fe7e7b067aed3c9387a5ac3d701e3698a7bcb7fd5c2dd4bba3a50d199d6a
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.150.223.102
- 20.247.185.124
- 52.123.252.230
- 4.230.171.124
- 52.110.12.24
- 172.64.154.167
- 162.159.142.9
- 172.66.2.5
- 52.110.12.38
- 52.110.12.19
- 4.150.223.111
- 4.150.223.113
- 135.234.160.244
- 20.42.179.192
- 52.123.252.236
- 52.123.252.223
- 135.233.45.221
- 52.148.114.188
- 172.178.240.163
- 52.110.12.46
- 52.110.12.16
- 72.153.5.132
More Dridex samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report