Summary | ZeroBOX

MfbNKrx.png

Dridex PE32 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6402 July 22, 2021, 10:58 a.m. July 22, 2021, 11:11 a.m.
Size 176.5KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 aae1e725e2dbfd91213be22e857f9d02
SHA256 3cba24dba02d5817a029caee6eadf1b3b4eb75ff861c62df3e4d4fbde1c349c2
CRC32 BD62FE4C
ssdeep 3072:TVadvfvemTEtQ9yoZPW/k/nklVtu77wBeZUCEQZRpdBDp57WQhdIif4:4DTyJWPd/nkdqw4/HdB77WQhdIu
Yara
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Win32_Trojan_Dridex_Gene_Zero - Win32 Trojan Dridex Gene
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x0001ea00', u'virtual_address': u'0x00008000', u'entropy': 7.744912578549469, u'name': u'.rdata', u'virtual_size': u'0x0001ea1a'} entropy 7.74491257855 description A section with a high entropy has been found
section {u'size_of_data': u'0x00006200', u'virtual_address': u'0x00027000', u'entropy': 6.886132830096508, u'name': u'.data', u'virtual_size': u'0x00007d80'} entropy 6.8861328301 description A section with a high entropy has been found
entropy 0.837606837607 description Overall entropy of this PE file is high