MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35daa69257a8ec1b204afcf40604021890e8d4343e37453d4c9b8ca8801e7d33. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 35daa69257a8ec1b204afcf40604021890e8d4343e37453d4c9b8ca8801e7d33
SHA3-384 hash: 51e16bea6ca108d4ba6b3454b908c1f619b6cb271efcb6120b8e704f8488f650bd9012f0d345ab0bc1d088c5178165f9
SHA1 hash: 117993fe3207b9f26ca0faef6a78e1854746d3c2
MD5 hash: ef132217d2b7866ee7d8b8635faf6de9
humanhash: stairway-lion-utah-cat
File name:19513687ead846bae3d6dc2187ebf1d00be.exe
Download: download sample
Signature TrickBot
File size:459'140 bytes
First seen:2020-04-22 08:43:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d2091b6df8b6ce72e745b9e2d419885d (135 x TrickBot)
ssdeep 12288:QboBb/W9ANGBAFb5i0P6HfewKQLYg0yCxp:4xBAiAHwfzu
Threatray 2'903 similar samples on MalwareBazaar
TLSH 93A4CF11BAE244E6DC59453C8BE29BB03F79AC10AFD35AD757907D0F68B01D08933AB6
Reporter JoulK
Tags:TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

Executable exe 35daa69257a8ec1b204afcf40604021890e8d4343e37453d4c9b8ca8801e7d33

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::SetConsoleCtrlHandler
KERNEL32.dll::SetStdHandle
WIN_USER_APIPerforms GUI ActionsUSER32.dll::CreateWindowExW

Comments