MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09da6102c6b77c609537c5b3d8bf9de8f4143d533856d174929859feda5806fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 09da6102c6b77c609537c5b3d8bf9de8f4143d533856d174929859feda5806fa
SHA3-384 hash: a67703914484dea13b950aed1001e35edef4f5140d533672e747efaa1ccafb62873bd5209de1a2323ddf9a9eed116c41
SHA1 hash: 26b6a975f3af21eb43986e08b5b5472e6dcbf770
MD5 hash: 830b5861063e0d5a94b9b895f5b58fe5
humanhash: texas-single-finch-stairway
File name:09da6102c6b77c609537c5b3d8bf9de8f4143d533856d174929859feda5806fa
Download: download sample
Signature TrickBot
File size:339'968 bytes
First seen:2020-11-10 11:14:42 UTC
Last seen:2024-07-24 11:02:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 3fbe968d4a91909b7a50f8f5a87ea911 (6 x TrickBot)
ssdeep 6144:lRHSF0OXIGBniCWbyJ40Eor+NAgTPsCwGOUaHfiAvvohqfp2:lZ5OXIGBniCWbyeyCigTPsCwr5xvvo7
TLSH DC741882D36B84BFD846D0BCB558C430DD6879368378A9BF73A403B12D625EB3A27750
Reporter seifreed
Tags:TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Sending a custom TCP request
Connection attempt
Connection attempt to an infection source
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
Multi AV Scanner detection for submitted file
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.BazarLoader
Status:
Malicious
First seen:
2020-11-10 11:18:26 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
bazarbackdoor
Score:
  10/10
Tags:
family:bazarbackdoor backdoor
Behaviour
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Program crash
Looks up external IP address via web service
BazarBackdoor
Suspicious use of NtCreateProcessExOtherParentProcess
Unpacked files
SH256 hash:
09da6102c6b77c609537c5b3d8bf9de8f4143d533856d174929859feda5806fa
MD5 hash:
830b5861063e0d5a94b9b895f5b58fe5
SHA1 hash:
26b6a975f3af21eb43986e08b5b5472e6dcbf770
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments