🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23
SHA3-384 hash: 955d28175608b59497a6af1ce943cedead6620226c6e0116733a957be21cd2e813a2eaa638544c8f4d39e2bc836eaa54
SHA1 hash: 03511959dd3ebe64bf6f9c4194076d435f6f0621
MD5 hash: 5adaaad9852f8358aeeb367f1cd26b76
humanhash: cardinal-snake-fruit-fourteen
File name:5adaaad9852f8358aeeb367f1cd26b76.dll
Download: download sample
Signature TrickBot
File size:450'560 bytes
First seen:2021-10-28 09:43:12 UTC
Last seen:2021-10-28 12:52:01 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash e501213c760138256f33c9d87d488b16 (1 x TrickBot)
ssdeep 6144:J6kDyTdDOoJtnIu5OLGjkBZg8slL5u8KTFuhPUZPKCu/0O12rwu8xoyo:J6QyTdDO24bFslaTFq2du/0C2t8xof
Threatray 7'908 similar samples on MalwareBazaar
TLSH T1BAA4F11273E1C172D1BA127D0E7B976293ABBC20DFB54A873B443A8D5E316C19E39352
File icon (PE):PE icon
dhash icon 71b119dcce576333 (3'570 x Heodo, 203 x TrickBot, 19 x Gh0stRAT)
Reporter abuse_ch
Tags:dll TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
281
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
greyware keylogger packed
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Delayed program exit found
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 510882 Sample: f8OmjKHVxK.dll Startdate: 28/10/2021 Architecture: WINDOWS Score: 100 35 ident.me 2->35 37 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->37 39 Found malware configuration 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 2 other signatures 2->43 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        14 cmd.exe 1 9->14         started        16 rundll32.exe 9->16         started        18 2 other processes 9->18 signatures6 53 Writes to foreign memory regions 11->53 55 Allocates memory in foreign processes 11->55 57 Queues an APC in another process (thread injection) 11->57 59 Delayed program exit found 11->59 20 wermgr.exe 11->20         started        23 cmd.exe 11->23         started        25 rundll32.exe 14->25         started        27 wermgr.exe 16->27         started        29 cmd.exe 16->29         started        process7 signatures8 45 Tries to detect virtualization through RDTSC time measurements 20->45 47 Found evasive API chain (trying to detect sleep duration tampering with parallel thread) 20->47 49 Writes to foreign memory regions 25->49 51 Allocates memory in foreign processes 25->51 31 wermgr.exe 25->31         started        33 cmd.exe 25->33         started        process9
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-10-27 23:04:59 UTC
AV detection:
7 of 28 (25.00%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:rob137 banker suricata trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Trickbot
suricata: ET MALWARE Win32/TrickBot CnC Initial Checkin M2
Malware Config
C2 Extraction:
65.152.201.203:443
185.56.175.122:443
46.99.175.217:443
179.189.229.254:443
46.99.175.149:443
181.129.167.82:443
216.166.148.187:443
46.99.188.223:443
128.201.76.252:443
62.99.79.77:443
60.51.47.65:443
24.162.214.166:443
45.36.99.184:443
97.83.40.67:443
184.74.99.214:443
103.105.254.17:443
62.99.76.213:443
82.159.149.52:443
Unpacked files
SH256 hash:
0d1fa54faea7fa77816fc999a0aed1620009ac3826e4bccb16c571541654d314
MD5 hash:
019330d0a3821c985b2f0017f3baf1df
SHA1 hash:
f2efffdc96acdcf1068c880257cdfa4feee36873
SH256 hash:
d82d1ff839ff7f127305f2a315a464e4e09a6db093034540d65316316bb0e63b
MD5 hash:
c6fb642f3e147274b82b0d9e66f52314
SHA1 hash:
670b8ef90a003f631a4db263342b6972acd1fdba
SH256 hash:
b2caf0753faa581f529667e00b14853c23b97085be9d1f10963e1b80e7c9c7c9
MD5 hash:
bffae9b262ec24336c47298c0eabd0a4
SHA1 hash:
5d063508c843025373704c28afb7dae6d69999bf
SH256 hash:
4b876066ed5d3b353936dd8eb3c78c5df9674a5525b6a8e8918d44359351375b
MD5 hash:
62ba7b087bc30c3dc5596c5532f977ac
SHA1 hash:
1ed63682757ad736d12b05a6e0663d94f3d862be
Detections:
win_trickbot_auto
SH256 hash:
0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23
MD5 hash:
5adaaad9852f8358aeeb367f1cd26b76
SHA1 hash:
03511959dd3ebe64bf6f9c4194076d435f6f0621
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll 0ed13cbfe863da2d2497ed2a3fdd1845b54fc312e9d6b3f666c503eb52780f23

(this sample)

  
Delivery method
Distributed via web download

Comments