General

  • Target

    71c62af59870564b311e61637616264171336dd48f63b8f0b4060650d0140571

  • Size

    117KB

  • MD5

    f4ba8eb55cf6b532d6e9ae016e28840b

  • SHA1

    48a6f0843e40776556fbc8edddc039f82a21f66e

  • SHA256

    71c62af59870564b311e61637616264171336dd48f63b8f0b4060650d0140571

  • SHA512

    371e08bdc361b1a2de6cd09d8fa77fdf83276d1c4d976e3d854dab0aa185ccbfeaa4912368900fd693f6f28cae7ab2cfdef3d60d80520d11632c0babe2dea43d

  • SSDEEP

    3072:SQ7UKo8ztdcDu3FZ0/497Vafu6KRe++Z6R6q:SYUKoAtdcDu1iw3ghuerZJ

Malware Config

Extracted

Family

dridex

Botnet

22201

C2

45.79.91.89:9987

157.245.231.228:6051

rc4.plain
rc4.plain

Signatures

  • Dridex Loader 1 IoCs

    Detects Dridex both x86 and x64 loader in memory.

  • Dridex family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 71c62af59870564b311e61637616264171336dd48f63b8f0b4060650d0140571
    .dll windows:6 windows x86 arch:x86

    68b66fd5fe2322f1f5fcb9cf4ede12bd


    Headers

    Imports

    Exports

    Sections