MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2824d4b0e5a502416696b189bd840870a19dfd555b53535f20b0c87c95f4c232. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2824d4b0e5a502416696b189bd840870a19dfd555b53535f20b0c87c95f4c232
SHA3-384 hash: 59e5e08603e8e675c43a33db6caa6c088a9add7e796ddcb0d69bf15dfcc076cfed976f4fd77b4b4b8c045aadde0ddd16
SHA1 hash: 45552e098f0f6c84f38f337fd75baf384f566f2d
MD5 hash: 4ea2fd7dfa35b87fc1faac4e3881be5c
humanhash: johnny-michigan-mockingbird-quebec
File name:2824d4b0e5a502416696b189bd840870a19dfd555b53535f20b0c87c95f4c232.bin
Download: download sample
Signature TrickBot
File size:24'576 bytes
First seen:2020-12-01 13:57:56 UTC
Last seen:2020-12-01 16:04:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7802a2afdb884b4d1a51c221c6ef5fcd (3 x BuerLoader, 2 x TrickBot)
ssdeep 384:bMd1wVcTN/p7Ff3Yunx02sdYda+12w515JaixQNctxyxQcMmZMIMyDsGU:AdS6TNxJXmdYd52w5HTd7yxRZvMssX
Threatray 7 similar samples on MalwareBazaar
TLSH FAB26D93749AC476C3202B751F85741292E86E2071B7E2F77A6C1CCC7CB4A9BD729352
Reporter Arkbird_SOLG
Tags:Buer Loader TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
177
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Antivirus / Scanner detection for submitted sample
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-12-01 13:58:05 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
2824d4b0e5a502416696b189bd840870a19dfd555b53535f20b0c87c95f4c232
MD5 hash:
4ea2fd7dfa35b87fc1faac4e3881be5c
SHA1 hash:
45552e098f0f6c84f38f337fd75baf384f566f2d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

TrickBot

Executable exe 2824d4b0e5a502416696b189bd840870a19dfd555b53535f20b0c87c95f4c232

(this sample)

Comments