MALICIOUS — ffa24be3e2cc8d7ac27bdce483537b73fdeef57e429883e91aef1589a812669b
MALICIOUS — ffa24be3e2cc8d7ac27bdce483537b73fdeef57e429883e91aef1589a812669b is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Dridex family. 3 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ffa24be3e2cc8d7ac27bdce483537b73fdeef57e429883e91aef1589a812669b - SHA-1:
7b4569a64978041530961dfe62dcda8a50e635a8 - MD5:
f653617810cb4c333fe7a72442d5543b - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
12288:JmC2cSr3fdhDv6QWbTUF2tNIkQoDaHWIGy8lcSiEUPtF04OhWqV6hOv6Z:d2c6WRTUUt+HxHGRivPX04OhWqVD6Z - TLSH:
T195515BCD53096B15D2328E687D528ECE1082B09A507E341D6D83CA3F2A64CA7FD73976 - Submitted as: ffa24be3e2cc8d7ac27bdce483537b73fdeef57e429883e91aef1589a812669b
- File type: pe · Size: 881215 bytes
- Verdict: malicious (98/100) · Family: Dridex
Detections (3 of 56 engines)
- ClamAV (daily): Win.Packed.Cerbu-9917004-0
- Microsoft Defender: Trojan:Win32/Dridex!pz
- Emsisoft (Emergency Kit): Gen:Variant.Ulise.317142
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Packed.Cerbu-9917004-0 (rule
Win.Packed.Cerbu-9917004-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Dridex!pz (rule
Trojan:Win32/Dridex!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ulise.317142 (rule
Gen:Variant.Ulise.317142) - engine signal, weight 0.55, confidence 0.85 - 1 behavioral detection(s) across 1 rule(s): LOLBin: rundll32 suspicious invocation [medium] (rule
tl-lolbin-rundll32) - dynamic signal, weight 0.40, confidence 0.90 - Embedded network infrastructure: 6.1.4.4 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
14915 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- time.windows.com
- 188.114.148.52.in-addr.arpa.
- 199.232.138.172
- 10.240.0.1
- 52.148.114.188 SG · Singapore · AS8075 Microsoft Corporation
Embedded domains
- 72.ua
Embedded IP addresses
- 6.1.4.4
- 52.148.114.188
File paths
- d:\agent\_work\3\s\src\vctools\crt\vcruntime\src\eh\std_type_info.cpp
- d:\agent\_work\3\s\src\vctools\crt\vcruntime\src\internal\per_thread_data.cpp
- C:\Program
- d:\agent\_work\3\s\src\vctools\crt\vcruntime\src\eh\std_exception.cpp
- d:\agent\_work\3\s\src\vctools\crt\vcruntime\src\internal\winapi_downlevel.cpp
More Dridex samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report