Report - MfbNKrx.png

Dridex PE32 DLL PE File
ScreenShot
Created 2021.07.22 13:11 Machine s1_win7_x6403
Filename MfbNKrx.png
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
1.2
ZERO API file : malware
VT API (file) 20 detected (AIDetect, malware2, Save, malicious, confidence, 100%, ZedlaF, lu8@ayNMVSni, Attribute, HighConfidence, ccmw, TrojanX, Generic@ML, RDML, mN2jEGaWcnNH, 2b8sEuZ4g, Drixed, Unsafe, Score, Emotet, Artemis, Static AI, Suspicious PE)
md5 aae1e725e2dbfd91213be22e857f9d02
sha256 3cba24dba02d5817a029caee6eadf1b3b4eb75ff861c62df3e4d4fbde1c349c2
ssdeep 3072:TVadvfvemTEtQ9yoZPW/k/nklVtu77wBeZUCEQZRpdBDp57WQhdIif4:4DTyJWPd/nkdqw4/HdB77WQhdIu
imphash 458d7355fbf070054838e3593829db8d
impfuzzy 6:ZKUHXQ1bXhrV92VUI579ym1XYBVoXCwUcrMAdvX6n:ZtAHp92VT579ym1XY3D4rxvX6
  Network IP location

Signature (2cnts)

Level Description
warning File has been identified by 20 AntiVirus engines on VirusTotal as malicious
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (4cnts)

Level Name Description Collection
danger Win32_Trojan_Dridex_Gene_Zero Win32 Trojan Dridex Gene binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

USER32.dll
 0x10008030 TranslateMessage
 0x10008034 GetWindowThreadProcessId
 0x10008038 FindWindowExA
WS2_32.dll
 0x10008040 accept
msvcrt.dll
 0x10008048 memset
ADVAPI32.dll
 0x10008000 AddUsersToEncryptedFile
 0x10008004 RegOverridePredefKey
MPRAPI.dll
 0x10008020 MprInfoDelete
SHLWAPI.dll
 0x10008028 PathRemoveBlanksA
KERNEL32.dll
 0x1000800c GlobalSize
 0x10008010 CloseHandle
 0x10008014 GetModuleFileNameA
 0x10008018 OutputDebugStringA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure