MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25ac7e0410299ac6572befc8784420ecbc829ab0db38a7eb46a83855b419212f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 25ac7e0410299ac6572befc8784420ecbc829ab0db38a7eb46a83855b419212f
SHA3-384 hash: 07b5d00b1a7895bf6631c173a363d68868fb01cf43928ae01a44e826886ebb8b949ecb53b8bdf919b6a6766610e2161c
SHA1 hash: 2ae7bfc177b53167208c22d70fd74593dd1505ef
MD5 hash: a898fd9994613274e733fb17e8a6faa0
humanhash: music-papa-robin-cardinal
File name:yas28.dll
Download: download sample
Signature TrickBot
File size:344'064 bytes
First seen:2020-04-16 18:45:29 UTC
Last seen:2020-04-16 19:41:24 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 7fd75a73ba86d86020e138ed294ac38f (1 x TrickBot)
ssdeep 6144:e+noR51k0orZdj3fDizzLkF/hIvwC3+ZtpXksQcUBx/JuFZMjv:dn+51kZtdj3f2zzLEhIvwCuBUDcUBx/L
Threatray 2'956 similar samples on MalwareBazaar
TLSH 0574DF023C5F9CF5D0491134D8CA6F6997797C09BAA1C583DB353BADDEB1390E92A20E
Reporter abuse_ch
Tags:dll TrickBot


Avatar
abuse_ch
TrickBot malspam

HELO: mail.mynetpharma.us
Sending IP: 158.69.188.69
From: "Loren Searle" <orderconfirmation@mynetpharma.us>
Subject: Order Confirmation, Bank transfer succesful
Attachment: INVOICE.275.doc

TrickBot payload URL:
https://gulfcrossings.com/yas28.dll

Intelligence


File Origin
# of uploads :
2
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2020-04-16 19:35:28 UTC
File Type:
PE (Dll)
Extracted files:
18
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

DLL dll 25ac7e0410299ac6572befc8784420ecbc829ab0db38a7eb46a83855b419212f

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::SetStdHandle

Comments