Summary | ZeroBOX

1d6vP.png

Dridex PE32 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6402 July 22, 2021, 10:15 a.m. July 22, 2021, 10:20 a.m.
Size 176.5KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 dc8803148639b547891db02a455575bb
SHA256 537866a96449444a54002776f34eecf053c23122a554a79f4743df0749aa8005
CRC32 56ECD942
ssdeep 3072:bVadvfvemTEtQ9yoZPW/k/nklVtu77wBeZUCEQZRp4BDp57WQhdIif4:gDTyJWPd/nkdqw4/H4B77WQhdIu
Yara
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Win32_Trojan_Dridex_Gene_Zero - Win32 Trojan Dridex Gene
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x0001ea00', u'virtual_address': u'0x00008000', u'entropy': 7.746010304352409, u'name': u'.rdata', u'virtual_size': u'0x0001e810'} entropy 7.74601030435 description A section with a high entropy has been found
section {u'size_of_data': u'0x00006200', u'virtual_address': u'0x00027000', u'entropy': 6.886132830096508, u'name': u'.data', u'virtual_size': u'0x00007f4a'} entropy 6.8861328301 description A section with a high entropy has been found
entropy 0.837606837607 description Overall entropy of this PE file is high