🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813
SHA3-384 hash: e217d6ec0a7cdd5bca2ce500afa708d58086820f767db2b669bc8de9762cf55e0c9890cc07f9d7f1dda6cc3a3004ce5f
SHA1 hash: aa851e5b4b2fec802fbd7830633a0a264d1e4f25
MD5 hash: 5aa474d6a2ad892107496cb83a75c9de
humanhash: oven-network-echo-social
File name:19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813
Download: download sample
Signature TrickBot
File size:339'968 bytes
First seen:2020-11-13 15:39:30 UTC
Last seen:2024-07-24 11:44:45 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 531aae11456eb57cb80cf37bd5c0bbd4 (8 x TrickBot)
ssdeep 3072:MH+D6J4VwU5IizqrAujDQRuyWn/zihw6WWOJJQAPOIs2TYZeR6lDWHlbC/4wLlZS:TUizyqRSmcJQ4vTYYR6lUg/4eCyBl7I
Threatray 2'933 similar samples on MalwareBazaar
TLSH B674BE017D4E8CF1C4501170989AABA6563E7D257B85C1C3FB353AAEDCB23C0EA7A25D
Reporter seifreed
Tags:TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
181
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 316090 Sample: B4aEcfguDR Startdate: 13/11/2020 Architecture: WINDOWS Score: 56 17 Antivirus / Scanner detection for submitted sample 2->17 19 Machine Learning detection for sample 2->19 7 B4aEcfguDR.exe 5 2->7         started        process3 signatures4 21 Tries to detect virtualization through RDTSC time measurements 7->21 10 B4aEcfguDR.exe 2 7->10         started        13 conhost.exe 7->13         started        process5 signatures6 23 Tries to detect virtualization through RDTSC time measurements 10->23 15 conhost.exe 10->15         started        process7
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2020-11-13 15:43:24 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:lib724 banker dave trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Loads dropped DLL
Dave packer
Executes dropped EXE
Trickbot
Malware Config
C2 Extraction:
5.182.211.215:443
144.91.76.208:443
185.99.2.57:443
134.119.191.38:443
195.123.238.17:443
95.171.16.42:443
85.204.116.238:443
185.234.72.242:443
178.157.82.227:443
185.90.61.9:443
45.148.120.205:443
85.204.116.241:443
5.1.81.68:443
51.81.112.191:443
23.239.84.138:443
194.5.250.180:443
194.87.93.114:443
190.214.13.2:449
181.129.104.139:449
181.112.157.42:449
181.129.134.18:449
131.161.253.190:449
121.100.19.18:449
202.29.215.114:449
171.100.142.238:449
190.136.178.52:449
45.6.16.68:449
110.232.76.39:449
122.50.6.122:449
103.12.161.194:449
36.91.45.10:449
103.227.147.82:449
96.9.77.56:449
103.5.231.188:449
110.93.15.98:449
200.171.101.169:449
Unpacked files
SH256 hash:
19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813
MD5 hash:
5aa474d6a2ad892107496cb83a75c9de
SHA1 hash:
aa851e5b4b2fec802fbd7830633a0a264d1e4f25
SH256 hash:
236d5e3d2b458b75983dfd5307ba4c9ca92b885b5e6b8b5028fe78c0feb1bf6f
MD5 hash:
d2354bcfa5b66a62d8a613d7ebd15ff2
SHA1 hash:
81ec14d5bbff32447f092ff4644305eaa71a888a
SH256 hash:
4b409515c784a5edff15a7bce93e17cfdcba63a3bfa4104092c3514df40bbfc7
MD5 hash:
0a7ee22afa46d03bca2711488f5650bc
SHA1 hash:
c8575f1694cc1af3b32125e29684ab71eb4950cd
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments