logo

Talking to Dridex (part 0) – inside the dropper

ID: fb553a55-80f4-59db-bb26-bab500761d23

STIX ID: report--fb553a55-80f4-59db-bb26-bab500761d23

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2015-11-10

Date Updated: 2026-04-19

Author: CERT Polska

...
...

This report analyzes a Dridex sample, showing how the stage1 dropper locates and parses an in-memory config structure to obtain botnet IDs and C2 IP:port addresses (example IPs and a sample hash are provided), how RC4 is used to encrypt/decrypt XML-based commands and modules (including a listed RC4 key), and how a two-stage loader decodes and injects a packed main DLL into Explorer using a custom in-memory PE loader — all details that support detection, hunting, and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.