Summary | ZeroBOX

dllmar.dll

Dridex PE32 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6401 July 7, 2021, 9:33 a.m. July 7, 2021, 9:33 a.m.
Size 176.5KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c2b80fa119a1f182a24569df973f6b44
SHA256 7c80c1cbca689063977ae3ea76bf38553e02819ecb28b48ec2b1c7d4633e6052
CRC32 46354760
ssdeep 3072:3JWgjeWy6Qn2EjqWHBFtvLSmZIMr1ckoXYZK1+5RUQ3cg5NwrSl+2wxvvVDqwl+a:30gdy6I29sSqD15oXYZTBMYwrSl+2wxU
Yara
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Dridex_Gene_Zero - Win32 Trojan Dridex Gene
  • IsDLL - (no description)
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x0001ec00', u'virtual_address': u'0x00007000', u'entropy': 7.723174694475976, u'name': u'.rdata', u'virtual_size': u'0x0001ea2c'} entropy 7.72317469448 description A section with a high entropy has been found
section {u'size_of_data': u'0x00006400', u'virtual_address': u'0x00026000', u'entropy': 6.883766898191934, u'name': u'.data', u'virtual_size': u'0x00007e88'} entropy 6.88376689819 description A section with a high entropy has been found
entropy 0.843304843305 description Overall entropy of this PE file is high
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
Cylance Unsafe
VIPRE Trojan.Win32.Tracur.d (v)
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
Alibaba Trojan:Win32/EmotetedCryptc.180910
CrowdStrike win/malicious_confidence_100% (W)
Symantec ML.Attribute.HighConfidence
APEX Malicious
Paloalto generic.ml
Kaspersky UDS:DangerousObject.Multi.Generic
NANO-Antivirus Virus.Win32.Gen.ccmw
MicroWorld-eScan Trojan.GenericKD.46590839
Avast FileRepMalware
McAfee-GW-Edition Drixed-FJX!C2B80FA119A1
FireEye Generic.mg.c2b80fa119a1f182
Sophos Mal/Generic-S
Webroot W32.Malware.Gen
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Dridex.GC!MTB
Acronis suspicious
McAfee Drixed-FJX!C2B80FA119A1
MAX malware (ai score=88)
Rising Trojan.Generic@ML.94 (RDML:3PF5Qj0DKvFIOulPeawmOw)
SentinelOne Static AI - Suspicious PE
BitDefenderTheta Gen:NN.ZedlaF.34790.lu8@aCHJXOii
AVG FileRepMalware