MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 7
| SHA256 hash: | 19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813 |
|---|---|
| SHA3-384 hash: | e217d6ec0a7cdd5bca2ce500afa708d58086820f767db2b669bc8de9762cf55e0c9890cc07f9d7f1dda6cc3a3004ce5f |
| SHA1 hash: | aa851e5b4b2fec802fbd7830633a0a264d1e4f25 |
| MD5 hash: | 5aa474d6a2ad892107496cb83a75c9de |
| humanhash: | oven-network-echo-social |
| File name: | 19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813 |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 339'968 bytes |
| First seen: | 2020-11-13 15:39:30 UTC |
| Last seen: | 2024-07-24 11:44:45 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 531aae11456eb57cb80cf37bd5c0bbd4 (8 x TrickBot) |
| ssdeep | 3072:MH+D6J4VwU5IizqrAujDQRuyWn/zihw6WWOJJQAPOIs2TYZeR6lDWHlbC/4wLlZS:TUizyqRSmcJQ4vTYYR6lUg/4eCyBl7I |
| Threatray | 2'933 similar samples on MalwareBazaar |
| TLSH | B674BE017D4E8CF1C4501170989AABA6563E7D257B85C1C3FB353AAEDCB23C0EA7A25D |
| Reporter | |
| Tags: | TrickBot |
Intelligence
File Origin
# of uploads :
2
# of downloads :
181
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
Malware
Maliciousness:
Behaviour
Creating a window
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2020-11-13 15:43:24 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
5/5
Verdict:
malicious
Label(s):
trickbot
Similar samples:
+ 2'923 additional samples on MalwareBazaar
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:lib724 banker dave trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Loads dropped DLL
Dave packer
Executes dropped EXE
Trickbot
Malware Config
C2 Extraction:
5.182.211.215:443
144.91.76.208:443
185.99.2.57:443
134.119.191.38:443
195.123.238.17:443
95.171.16.42:443
85.204.116.238:443
185.234.72.242:443
178.157.82.227:443
185.90.61.9:443
45.148.120.205:443
85.204.116.241:443
5.1.81.68:443
51.81.112.191:443
23.239.84.138:443
194.5.250.180:443
194.87.93.114:443
190.214.13.2:449
181.129.104.139:449
181.112.157.42:449
181.129.134.18:449
131.161.253.190:449
121.100.19.18:449
202.29.215.114:449
171.100.142.238:449
190.136.178.52:449
45.6.16.68:449
110.232.76.39:449
122.50.6.122:449
103.12.161.194:449
36.91.45.10:449
103.227.147.82:449
96.9.77.56:449
103.5.231.188:449
110.93.15.98:449
200.171.101.169:449
144.91.76.208:443
185.99.2.57:443
134.119.191.38:443
195.123.238.17:443
95.171.16.42:443
85.204.116.238:443
185.234.72.242:443
178.157.82.227:443
185.90.61.9:443
45.148.120.205:443
85.204.116.241:443
5.1.81.68:443
51.81.112.191:443
23.239.84.138:443
194.5.250.180:443
194.87.93.114:443
190.214.13.2:449
181.129.104.139:449
181.112.157.42:449
181.129.134.18:449
131.161.253.190:449
121.100.19.18:449
202.29.215.114:449
171.100.142.238:449
190.136.178.52:449
45.6.16.68:449
110.232.76.39:449
122.50.6.122:449
103.12.161.194:449
36.91.45.10:449
103.227.147.82:449
96.9.77.56:449
103.5.231.188:449
110.93.15.98:449
200.171.101.169:449
Unpacked files
SH256 hash:
19cd0e5a221a36279a046ef3dc2cfa90aca933c9a09a47bbf70a666e17556813
MD5 hash:
5aa474d6a2ad892107496cb83a75c9de
SHA1 hash:
aa851e5b4b2fec802fbd7830633a0a264d1e4f25
SH256 hash:
236d5e3d2b458b75983dfd5307ba4c9ca92b885b5e6b8b5028fe78c0feb1bf6f
MD5 hash:
d2354bcfa5b66a62d8a613d7ebd15ff2
SHA1 hash:
81ec14d5bbff32447f092ff4644305eaa71a888a
SH256 hash:
4b409515c784a5edff15a7bce93e17cfdcba63a3bfa4104092c3514df40bbfc7
MD5 hash:
0a7ee22afa46d03bca2711488f5650bc
SHA1 hash:
c8575f1694cc1af3b32125e29684ab71eb4950cd
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Emotet
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Delivery method
Other
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.