MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 32682ea9ee36a960cf405dbcc69d9140e82c07494f66b234dd6eca1a72a4d398. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 11
| SHA256 hash: | 32682ea9ee36a960cf405dbcc69d9140e82c07494f66b234dd6eca1a72a4d398 |
|---|---|
| SHA3-384 hash: | dbb96a6bc983f51f369a7401dd174c967f8daf0921377c7431017b454f4843309d0af514e2e8211a8fa78a0920f5c00d |
| SHA1 hash: | d572dd11bd04295c98ced1e8f104c15613919194 |
| MD5 hash: | 4fc9c825d7f504f3db1608bc014a44e4 |
| humanhash: | social-two-charlie-zebra |
| File name: | 4fc9c825d7f504f3db1608bc014a44e4.dll |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 675'840 bytes |
| First seen: | 2021-03-16 19:07:03 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 25a3bf96f64b55a69d3aaf04f6c99acc (3 x TrickBot) |
| ssdeep | 12288:G+QjOdLU2K5HmTbKbKKMFZys7tmwp1vWXZt+jztlhkLOMcZ6IlA:t/LUfU6Mjvp1oZt+XTMli |
| Threatray | 4 similar samples on MalwareBazaar |
| TLSH | 9EE46C8EE062C0B1D07960B4AF165B35919DDAD13E2F898392E4FD4ADD237D1869F3C2 |
| Reporter | |
| Tags: | dll mon129 TrickBot |
Intelligence
File Origin
# of uploads :
1
# of downloads :
299
Origin country :
n/a
Vendor Threat Intelligence
Detection:
TrickBot
Result
Verdict:
Malware
Maliciousness:
Behaviour
Sending a UDP request
Verdict:
Malicious
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Yara detected Trickbot
Behaviour
Behavior Graph:
Detection:
trickbot
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2021-03-15 17:29:38 UTC
AV detection:
20 of 28 (71.43%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Similar samples:
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:mon129 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
103.225.138.94:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
Unpacked files
SH256 hash:
ed728ceaa445efc7fd230501a53cd46757c532ef2bfda092e5b1aa20ad40d7b6
MD5 hash:
2cfa923f57cee7efec1451ab971bd64b
SHA1 hash:
25ca13a1a2f08c4c4880d75fd86c947fb3c1b0ae
Detections:
win_trickbot_a4
win_trickbot_auto
SH256 hash:
4d73facde3b7313b3699ef2093c56b1e2007c28a41584a4a63a08c586e25fabc
MD5 hash:
84571403571d4f13148a2befd5003c8c
SHA1 hash:
34157997136061be07dd306bd69cb923000aa505
SH256 hash:
d224997b2e15b0d2664b669845bac818c124e7b521a2d02a5dbba5ff06ef2b95
MD5 hash:
b63c57e591210f6d17deaff4b766206d
SHA1 hash:
b17dcdafcd2efbadb8ffaee82268a96fc8606f29
SH256 hash:
32682ea9ee36a960cf405dbcc69d9140e82c07494f66b234dd6eca1a72a4d398
MD5 hash:
4fc9c825d7f504f3db1608bc014a44e4
SHA1 hash:
d572dd11bd04295c98ced1e8f104c15613919194
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Tinba
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.