Dridex Malware Analizi
Dosya Ozellikleri
SHA256: 1db8232b2f58470d4623be24b53f09004e8c4cef36c58aa0cb6dcbdf3d9f3130
MD5: beaedbb30159484696b7c36db88231f3
Dosya Tipi: exe
Boyut: 937,984 byte
Ilk Gorulme: 2022-03-23
AV Imzasi: Dridex
Imphash: 7be87787770ca1ffe5c8c785748fac0c
Raporlayan: JAMESWT_WT
Etiketler: Dridex, exe
Statik analiz: metadata tabanli (ornek indirilmedi)
Dridex — 악성코드 프로필
Dridex Bugat TA505 banking trojan. Chrome/Firefox form hooking with obfuscated strings. DirectUI RTTI.
기술 세부 정보
Dridex (Bugat/Cridex) is a modular banking trojan operated by TA505/Evil Corp since 2011. Uses peer-to-peer botnet architecture for C2 communication to resist takedowns. Modules: form grabber, VNC backdoor, network proxy, credential stealer, spread module. Encrypted communication: RC4 + custom protocol over HTTP. Delivered via Microsoft Office macro phishing (VBA macros). Used to deliver: BitPaymer, WastedLocker, Grief (PayOrGrief) ransomware. Evil Corp sanctioned by US Treasury October 2019, making ransom payments illegal for US entities. Dridex infrastructure heavily overlaps with Locky ransomware campaigns. Botnet IDs (bot IDs): 220, 444, 7777, multiple active botnets simultaneously.
귀속 / 위협 행위자
Evil Corp (TA505), Maksim Yakubets (indicted by FBI)
기능 및 동작
IOC 목록 (1 개 지표)
# FILEPATH
1db8232b2f58470d4623be24b53f09004e8c4cef36c58aa0cb6dcbdf3d9f3130
| 유형 | 값 | 메모 |
|---|---|---|
| filepath | 1db8232b2f58470d4623be24b53f09004e8c4cef36c58aa0cb6dcbdf3d9f3130 | PDB |
C2 서버 (이 패밀리에 대해 3개의 서버 기록)
| 주소 | 유형 | 포트 | 프로토콜 | 상태 | 국가 |
|---|---|---|---|---|---|
| 79.141.164.52 | ip | 4444 | TCP | sinkholed | RO |
| 185.234.218.151 | ip | 4444 | HTTPS | sinkholed | RU |
| 77.73.133.84 | ip | 443 | HTTPS | sinkholed | BG |
C2 주소는 KEYDAL 팀이 수동으로 검증한 악성코드 샘플에서만 제공됩니다. 상업적 사용은 금지됩니다.