🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07048e9764891e39f3e37c72c8ca33a6a01cbd359cd47c12a3af7726769e83b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 07048e9764891e39f3e37c72c8ca33a6a01cbd359cd47c12a3af7726769e83b8
SHA3-384 hash: 0b221e5bd1ba35bcd27e9a611847b45a41c7b2a969ad5c400b7e084a50c221d7cda9650d6caa12f766c923bf5c292f63
SHA1 hash: a05fcb08123e2ce5385081ce5b57e6dd211b9c3c
MD5 hash: 10dcb25376d06bc580d053b982f2d9a3
humanhash: spaghetti-michigan-batman-missouri
File name:mon88.dll
Download: download sample
Signature TrickBot
File size:700'416 bytes
First seen:2021-02-26 21:56:40 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 40ff08599d2f6598f40f9e3b7d8a26d3 (3 x TrickBot)
ssdeep 12288:nD3OJc3A4jSMNkNLJxImKT7udOCDZ9rpGhTWFqZ1fWCKpR/bUfQ8t+3zwiaY5r1v:D3OJc3A42Vr1mc1UMn4GCl7
Threatray 25 similar samples on MalwareBazaar
TLSH 5CE42826B174C835C7B98635CDE2AAAC72E5BC31DD50A513B690B74E7A37B80C919333
Reporter Cryptolaemus1
Tags:dll mon88 TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
227
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changing a file
Launching the default Windows debugger (dwwin.exe)
Sending a UDP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
9 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-02-26 21:08:45 UTC
AV detection:
4 of 29 (13.79%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:mon88 banker trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
41.77.134.250:449
45.155.173.242:443
192.162.238.186:449
142.112.79.223:449
122.2.28.70:449
154.126.176.30:449
45.230.244.20:443
182.253.107.34:443
200.52.147.93:443
123.200.26.246:449
131.255.106.152:449
177.85.133.118:449
103.225.138.94:449
142.202.191.164:443
95.210.118.90:449
36.94.62.207:443
201.20.118.122:449
180.92.238.186:449
103.130.6.244:449
202.91.41.138:449
187.20.217.129:449
Unpacked files
SH256 hash:
07048e9764891e39f3e37c72c8ca33a6a01cbd359cd47c12a3af7726769e83b8
MD5 hash:
10dcb25376d06bc580d053b982f2d9a3
SHA1 hash:
a05fcb08123e2ce5385081ce5b57e6dd211b9c3c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll 07048e9764891e39f3e37c72c8ca33a6a01cbd359cd47c12a3af7726769e83b8

(this sample)

  
Delivery method
Distributed via web download

Comments