🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 046ea30e67d2a06b83db596a087b9e62bd23de95e76aefb6deb3c9348c546c48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: 046ea30e67d2a06b83db596a087b9e62bd23de95e76aefb6deb3c9348c546c48
SHA3-384 hash: 465bb60db67be09c5c8d3736a4e345d2114249892520a02f8b213237380c3262939ca5ce8a5d0349ee86bc5ac9654815
SHA1 hash: 8c6ecaa004539de964356791f86f0478bdb540cb
MD5 hash: 9ce3657c4801c085594c492e4948c4d7
humanhash: river-two-alabama-juliet
File name:LisectAVT_2403002C_42.dll
Download: download sample
Signature TrickBot
File size:410'767 bytes
First seen:2024-07-25 01:48:00 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 3da17812d53e4c8ea40facb22cec21c8 (2 x TrickBot)
ssdeep 6144:SYbxqY1tkUnvIRKYdZEMiXeUJqFfEGTJ210yGCZ0AlBqhmkh3brRLeeuXkHlFWkr:jxqY1tzwRKYdiMiXvqFfX2St6VmASvl
Threatray 3 similar samples on MalwareBazaar
TLSH T18594E1217280C076D3CB2179DEB197710AAABC1257B0A4CB7BE52FBE4F642D1977430A
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
File icon (PE):PE icon
dhash icon d49c8ca6a7b3e363 (2 x TrickBot)
Reporter Anonymous
Tags:dll exe TrickBot


Avatar
Anonymous
this malware sample is very nasty!

Intelligence


File Origin
# of uploads :
1
# of downloads :
866
Origin country :
CN CN
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
epmicrosoft_visual_cc fingerprint microsoft_visual_cc overlay packed
Result
Threat name:
Trickbot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2024-07-25 01:48:14 UTC
File Type:
PE (Dll)
Extracted files:
4
AV detection:
30 of 38 (78.95%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:zev4 banker discovery trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Trickbot
Malware Config
C2 Extraction:
14.232.161.45:443
118.173.233.64:443
41.57.156.203:443
45.239.234.2:443
45.201.136.3:443
177.10.90.29:443
185.17.105.236:443
91.237.161.87:443
185.189.55.207:443
186.225.119.170:443
143.0.208.20:443
222.124.16.74:443
220.82.64.198:443
200.236.218.62:443
178.216.28.59:443
45.239.233.131:443
196.216.59.174:443
119.202.8.249:443
82.159.149.37:443
49.248.217.170:443
181.114.215.239:443
113.160.132.237:443
105.30.26.50:443
202.165.47.106:443
103.122.228.44:443
Unpacked files
SH256 hash:
8d8f9eaa18d7f31089aba7aacafa780d4b24bcf35875d7652c718839be8e169e
MD5 hash:
cadda584eff70f882818afeb8d849cab
SHA1 hash:
f02e8fdf88c23115adc3d8ceb3253ed82c82135b
Detections:
win_trickbot_auto
SH256 hash:
046ea30e67d2a06b83db596a087b9e62bd23de95e76aefb6deb3c9348c546c48
MD5 hash:
9ce3657c4801c085594c492e4948c4d7
SHA1 hash:
8c6ecaa004539de964356791f86f0478bdb540cb
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

DLL dll 046ea30e67d2a06b83db596a087b9e62bd23de95e76aefb6deb3c9348c546c48

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments