Managed XDR

vtdl_217xok5q (Dridex) — malware analysis report

File info

Filename
vtdl_217xok5q
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
File size
236 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6f4427b85ae96cc4ed4f5eda494f5e762425e96d
SHA256
ea179d04fea1f3de62206158bd1c7633d955c2919a1f8629b572d9b7337a0e99
MD5
90dbc4147621b3737f82a92bb6003c9d

Malwares

  • Dridex

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
ce_info: Dridex Configuration Data found
no_graphical_activity: No graphic activity
message_box: Displays a message

Related reports