🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36075270b200f59a2566b17bcff24f6574d8b3d476d4177f0aebedb4442da2f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 36075270b200f59a2566b17bcff24f6574d8b3d476d4177f0aebedb4442da2f2
SHA3-384 hash: c26cc386d1713b8a3dd7ace79438465e43c8d8e6a53f9b0bf412dc952df50a3682fb304714e9bef1cb6681610084402f
SHA1 hash: 3ddc2b46459632c8b35896e64dbb746882f681a8
MD5 hash: 7a330e9128cadfafe0204ae241c8b062
humanhash: solar-north-alabama-maine
File name:7a330e91_by_Libranalysis
Download: download sample
Signature TrickBot
File size:176'412 bytes
First seen:2021-05-25 16:02:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:ZVpUc12yjNv8cQS+mHIjBasCFify7x0Xz49T1vgvT10OHPZh:RUc1hv8cQS+mojBXC061k49yT19vP
TLSH 19041335B8D7D8257F272D36608152621BF77B6242192E85A34B90E4F6B742FB300F7A
Reporter Libranalysis
Tags:TrickBot


Avatar
Libranalysis
Uploaded as part of the sample sharing project

Intelligence


File Origin
# of uploads :
1
# of downloads :
607
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Document-Excel.Downloader.EncDoc
Status:
Malicious
First seen:
2021-05-25 16:02:21 UTC
AV detection:
15 of 46 (32.61%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
macro xlm
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Process spawned unexpected child process
Malware Config
Dropper Extraction:
http://103.155.92.82/44341.6708174769.dat
http://45.90.59.64/44341.6708174769.dat
http://80.92.206.168/44341.6708174769.dat
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments