Summary | ZeroBOX

Kbf2P.png

Dridex PE32 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6401 July 22, 2021, 10:57 a.m. July 22, 2021, 11:07 a.m.
Size 175.5KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 45d9d9c13a4b2f77a5635a64cd58bd03
SHA256 e26c7e7c111e41d766ab313e1c4c0f17cbc9710aee23248b017735caf97f2a0e
CRC32 6F00F4E3
ssdeep 3072:Zb35eJIBwzBgXbJ26juQdZHT5K4PrsF2ATdwNBJUiG7NNNNNNNNNNNNNNNuetbX4:ZNe2Gzm1dZtK4Puhha87NNNNNNNNNNNI
Yara
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Win32_Trojan_Dridex_Gene_Zero - Win32 Trojan Dridex Gene
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x0001ea00', u'virtual_address': u'0x00007000', u'entropy': 7.740525566846312, u'name': u'.rdata', u'virtual_size': u'0x0001e978'} entropy 7.74052556685 description A section with a high entropy has been found
section {u'size_of_data': u'0x00006400', u'virtual_address': u'0x00026000', u'entropy': 6.881183365279174, u'name': u'.data', u'virtual_size': u'0x00007f50'} entropy 6.88118336528 description A section with a high entropy has been found
entropy 0.845272206304 description Overall entropy of this PE file is high
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
Symantec ML.Attribute.HighConfidence
APEX Malicious
NANO-Antivirus Virus.Win32.Gen.ccmw
Rising Trojan.Generic@ML.80 (RDML:BaGwa6+GgK44c0ERRlhYRw)
Sophos ML/PE-A
FireEye Generic.mg.45d9d9c13a4b2f77
eGambit Unsafe.AI_Score_99%
Cynet Malicious (score: 100)
Acronis suspicious
SentinelOne Static AI - Suspicious PE
BitDefenderTheta Gen:NN.ZedlaF.34050.ku8@aqjVTdpi