MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97c6fdb81fcc7d56b44c314ad21d2ef5e85299e18cff95cebc54b9192c025902. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 97c6fdb81fcc7d56b44c314ad21d2ef5e85299e18cff95cebc54b9192c025902
SHA3-384 hash: bd0cc3efa093faa55aae21a9404c5c0da2b8f2381168b3c8d8ada3ad2bc2f9b7b7a37f401384ece90978295639ee2bfc
SHA1 hash: 903440d349190360ce0fc84bd6c32f3e9a95a02c
MD5 hash: f93a2db1e096cc876b72aeaae82451f9
humanhash: vermont-nebraska-vegan-eleven
File name:update.dll
Download: download sample
Signature TrickBot
File size:393'728 bytes
First seen:2020-07-08 05:39:50 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 89ed1bc251d6c3e47d163c5f895ad913 (7 x TrickBot)
ssdeep 6144:nMhYHYPwSmAO7AOFmBU7qwVp4VLmX9CeXc47hZgl:nMKHmxmZiB4qwuVKFn7vW
Threatray 5'023 similar samples on MalwareBazaar
TLSH 4B84DF0075E2C0B2C47E23B76A1AAFB10269FD118B68D9F777E81E0E6D742C07677652
Reporter abuse_ch
Tags:chil61 dll GBR geo TrickBot


Avatar
abuse_ch
Malspam distributing TrickBot:

HELO: host.tomaxusa.com
Sending IP: 69.167.150.46
From: Walker <orders@tomaxusa.com>
Subject: The IRS form improvements along with probable fine notification email
Attachment: Form_1099_1793465.xls

TrickBot payload URL:
http://185.180.197.66/2VJDZ6JaqzEiq.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Unauthorized injection to a system process
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2020-07-08 05:41:05 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

DLL dll 97c6fdb81fcc7d56b44c314ad21d2ef5e85299e18cff95cebc54b9192c025902

(this sample)

Comments