MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 10
| SHA256 hash: | 0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23 |
|---|---|
| SHA3-384 hash: | 955d28175608b59497a6af1ce943cedead6620226c6e0116733a957be21cd2e813a2eaa638544c8f4d39e2bc836eaa54 |
| SHA1 hash: | 03511959dd3ebe64bf6f9c4194076d435f6f0621 |
| MD5 hash: | 5adaaad9852f8358aeeb367f1cd26b76 |
| humanhash: | cardinal-snake-fruit-fourteen |
| File name: | 5adaaad9852f8358aeeb367f1cd26b76.dll |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 450'560 bytes |
| First seen: | 2021-10-28 09:43:12 UTC |
| Last seen: | 2021-10-28 12:52:01 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | e501213c760138256f33c9d87d488b16 (1 x TrickBot) |
| ssdeep | 6144:J6kDyTdDOoJtnIu5OLGjkBZg8slL5u8KTFuhPUZPKCu/0O12rwu8xoyo:J6QyTdDO24bFslaTFq2du/0C2t8xof |
| Threatray | 7'908 similar samples on MalwareBazaar |
| TLSH | T1BAA4F11273E1C172D1BA127D0E7B976293ABBC20DFB54A873B443A8D5E316C19E39352 |
| File icon (PE): | |
| dhash icon | 71b119dcce576333 (3'570 x Heodo, 203 x TrickBot, 19 x Gh0stRAT) |
| Reporter | |
| Tags: | dll TrickBot |
Intelligence
File Origin
# of uploads :
2
# of downloads :
281
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
greyware keylogger packed
Malware family:
TrickBot
Verdict:
Malicious
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Delayed program exit found
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-10-27 23:04:59 UTC
AV detection:
7 of 28 (25.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
trickbot
Similar samples:
+ 7'898 additional samples on MalwareBazaar
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:rob137 banker suricata trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Trickbot
suricata: ET MALWARE Win32/TrickBot CnC Initial Checkin M2
Malware Config
C2 Extraction:
65.152.201.203:443
185.56.175.122:443
46.99.175.217:443
179.189.229.254:443
46.99.175.149:443
181.129.167.82:443
216.166.148.187:443
46.99.188.223:443
128.201.76.252:443
62.99.79.77:443
60.51.47.65:443
24.162.214.166:443
45.36.99.184:443
97.83.40.67:443
184.74.99.214:443
103.105.254.17:443
62.99.76.213:443
82.159.149.52:443
185.56.175.122:443
46.99.175.217:443
179.189.229.254:443
46.99.175.149:443
181.129.167.82:443
216.166.148.187:443
46.99.188.223:443
128.201.76.252:443
62.99.79.77:443
60.51.47.65:443
24.162.214.166:443
45.36.99.184:443
97.83.40.67:443
184.74.99.214:443
103.105.254.17:443
62.99.76.213:443
82.159.149.52:443
Unpacked files
SH256 hash:
0d1fa54faea7fa77816fc999a0aed1620009ac3826e4bccb16c571541654d314
MD5 hash:
019330d0a3821c985b2f0017f3baf1df
SHA1 hash:
f2efffdc96acdcf1068c880257cdfa4feee36873
SH256 hash:
d82d1ff839ff7f127305f2a315a464e4e09a6db093034540d65316316bb0e63b
MD5 hash:
c6fb642f3e147274b82b0d9e66f52314
SHA1 hash:
670b8ef90a003f631a4db263342b6972acd1fdba
SH256 hash:
b2caf0753faa581f529667e00b14853c23b97085be9d1f10963e1b80e7c9c7c9
MD5 hash:
bffae9b262ec24336c47298c0eabd0a4
SHA1 hash:
5d063508c843025373704c28afb7dae6d69999bf
SH256 hash:
4b876066ed5d3b353936dd8eb3c78c5df9674a5525b6a8e8918d44359351375b
MD5 hash:
62ba7b087bc30c3dc5596c5532f977ac
SHA1 hash:
1ed63682757ad736d12b05a6e0663d94f3d862be
Detections:
win_trickbot_auto
SH256 hash:
0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23
MD5 hash:
5adaaad9852f8358aeeb367f1cd26b76
SHA1 hash:
03511959dd3ebe64bf6f9c4194076d435f6f0621
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.96
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.