🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e2f674241de56d4404a8fdbcb470fd9738d48c855fb0785deaae99ea3af383f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: 2e2f674241de56d4404a8fdbcb470fd9738d48c855fb0785deaae99ea3af383f
SHA3-384 hash: f172fee830c3d49fc4f83657ee69f4dfcdcc73f7ea5e8b077e5916aeb6cd6317f9dfeaaa02dad6595d551dbf285b97fb
SHA1 hash: 6b5045282bfb648754bbd3d40706fde1ee6dd7c3
MD5 hash: ffec9f3d109cd570f9a2962adc6f14c1
humanhash: echo-alpha-gee-arizona
File name:REQUEST FOR QUOTATION_NEW ORDER LISTED URGENTLY NEEDED.exe
Download: download sample
Signature TrickBot
File size:1'020'416 bytes
First seen:2022-12-12 14:31:54 UTC
Last seen:2022-12-16 15:51:20 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'234 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 24576:gszQve9P6I2wgNd3lRZCrHi8LGRDi66pFkf:gszSUwNd1nj8LGBh
Threatray 5'563 similar samples on MalwareBazaar
TLSH T1AB255AD1B7F2A125F68B32712418728DED35BD433647A15A27763B4082F58FFAAB8443
TrID 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.0% (.EXE) Win64 Executable (generic) (10523/12/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.2% (.EXE) Win32 Executable (generic) (4505/5/1)
1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Reporter James_inthe_box
Tags:exe TrickBot

Intelligence


File Origin
# of uploads :
4
# of downloads :
564
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
REQUEST FOR QUOTATION_NEW ORDER LISTED URGENTLY NEEDED.exe
Verdict:
Malicious activity
Analysis date:
2022-12-12 14:34:31 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Сreating synchronization primitives
Launching a process
Creating a process with a hidden window
Running batch commands
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Unknown
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Antivirus detection for dropped file
Creates autostart registry keys with suspicious names
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Scheduled temp file as task from temp location
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 765422 Sample: REQUEST FOR QUOTATION_NEW O... Startdate: 12/12/2022 Architecture: WINDOWS Score: 100 95 mail.shubhdacargo.com 2->95 105 Antivirus detection for dropped file 2->105 107 Sigma detected: Scheduled temp file as task from temp location 2->107 109 Multi AV Scanner detection for submitted file 2->109 111 6 other signatures 2->111 12 REQUEST FOR QUOTATION_NEW ORDER LISTED URGENTLY NEEDED.exe 7 2->12         started        16 kHaNnkEj.exe 5 2->16         started        18 systems.exe 2->18         started        20 systems.exe 2->20         started        signatures3 process4 file5 81 C:\Users\user\AppData\Roaming\kHaNnkEj.exe, PE32 12->81 dropped 83 C:\Users\...\kHaNnkEj.exe:Zone.Identifier, ASCII 12->83 dropped 85 C:\Users\user\AppData\Local\...\tmpFAF3.tmp, XML 12->85 dropped 87 REQUEST FOR QUOTAT...NTLY NEEDED.exe.log, ASCII 12->87 dropped 127 Adds a directory exclusion to Windows Defender 12->127 129 Injects a PE file into a foreign processes 12->129 22 REQUEST FOR QUOTATION_NEW ORDER LISTED URGENTLY NEEDED.exe 4 4 12->22         started        26 powershell.exe 21 12->26         started        28 schtasks.exe 1 12->28         started        131 Multi AV Scanner detection for dropped file 16->131 133 Machine Learning detection for dropped file 16->133 30 schtasks.exe 16->30         started        32 kHaNnkEj.exe 16->32         started        34 schtasks.exe 18->34         started        36 systems.exe 18->36         started        signatures6 process7 file8 75 C:\Users\user\Desktop\systems.exe, PE32 22->75 dropped 77 C:\Users\user\...\systems.exe:Zone.Identifier, ASCII 22->77 dropped 79 C:\Users\user\AppData\Local\...\install.vbs, data 22->79 dropped 117 Creates autostart registry keys with suspicious names 22->117 38 wscript.exe 1 22->38         started        41 wscript.exe 22->41         started        44 wscript.exe 22->44         started        54 3 other processes 22->54 46 conhost.exe 26->46         started        48 conhost.exe 28->48         started        50 conhost.exe 30->50         started        52 conhost.exe 34->52         started        signatures9 process10 dnsIp11 113 System process connects to network (likely due to code injection or exploit) 38->113 56 cmd.exe 38->56         started        97 mail.shubhdacargo.com 162.215.248.64, 49699, 49700, 49701 PUBLIC-DOMAIN-REGISTRYUS United States 41->97 115 Modifies existing user documents (likely ransomware behavior) 41->115 99 192.168.2.1 unknown unknown 44->99 signatures12 process13 process14 58 systems.exe 56->58         started        61 conhost.exe 56->61         started        signatures15 119 Multi AV Scanner detection for dropped file 58->119 121 Machine Learning detection for dropped file 58->121 123 Adds a directory exclusion to Windows Defender 58->123 125 Injects a PE file into a foreign processes 58->125 63 systems.exe 58->63         started        67 powershell.exe 58->67         started        69 schtasks.exe 58->69         started        process16 file17 89 C:\Users\...\time_2022.12.12_18.00.49.png, PNG 63->89 dropped 91 C:\Users\...\time_2022.12.12_17.32.46.png, PNG 63->91 dropped 93 C:\Users\...\time_2022.12.12_17.03.44.png, PNG 63->93 dropped 101 Installs a global keyboard hook 63->101 103 Modifies existing user documents (likely ransomware behavior) 63->103 71 conhost.exe 67->71         started        73 conhost.exe 69->73         started        signatures18 process19
Threat name:
Win32.Trojan.Tiggre
Status:
Malicious
First seen:
2022-12-10 17:42:35 UTC
File Type:
PE (.Net Exe)
Extracted files:
18
AV detection:
23 of 26 (88.46%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
persistence
Behaviour
Creates scheduled task(s)
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
9389e6b99f24e6d253db6da5ddfe5a90d65c5e9c1d9c51e97b9f96a4411cdb80
MD5 hash:
de076abb01cfa00fe016ac0837c5c9c6
SHA1 hash:
930be878f888ad517d9632823cdd7ed76eb43662
SH256 hash:
922915132a628d0050bf03a473370544dde3323627fb4adcba3f1ba869537e50
MD5 hash:
1ecb63625d636b0b8f8ebdece9fa80c3
SHA1 hash:
5623d5ad21fc63893011bae7e4709c51219fcc1c
SH256 hash:
e821faf9c2d1381a8022ed7ff143189e48386c519bef514372253146eec56534
MD5 hash:
a3bdeb2d28f7d0b15408e8aaa10241ac
SHA1 hash:
50f7ed9ab84986673404c6af707787b651c2e2ba
SH256 hash:
b3869fa1b3ddb1601de35321e1a5283d5edd0e6c2e1b23353cf9cd2d0242f6c4
MD5 hash:
7127bca76766c6a9deaf1b0e614dfcda
SHA1 hash:
18b7d4d2e06af64eb356dfff20662834c3e21166
SH256 hash:
da6961e66fbe2488923447770b28810b7a3aefa11310b414bc247159b542514b
MD5 hash:
07b007d11b4d1444caf5b15122d2f701
SHA1 hash:
e62e77fad1b631ae917262adb33873422e63cc32
SH256 hash:
82a8d91f408fbe9e600f7a61380413f7634afe0c0c0ad742e5efd17d2cfa189c
MD5 hash:
f43ba8fa3ba45503586330e9ec18eeea
SHA1 hash:
20d353fec33db5424a1f7c083c2144091a20f8dc
SH256 hash:
2e2f674241de56d4404a8fdbcb470fd9738d48c855fb0785deaae99ea3af383f
MD5 hash:
ffec9f3d109cd570f9a2962adc6f14c1
SHA1 hash:
6b5045282bfb648754bbd3d40706fde1ee6dd7c3
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

Executable exe 2e2f674241de56d4404a8fdbcb470fd9738d48c855fb0785deaae99ea3af383f

(this sample)

Comments