🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98
SHA3-384 hash: 595f20594c7cff4ae86fce9f2f95e107d96c8c7bbc6676555849430703d3d7014ec5933988288e13cda3580eb8d1b136
SHA1 hash: 05acc14a076af1e2696faa5fa4e32778e55ec27f
MD5 hash: d48404abfb5c8a7bac7f9f619da899e9
humanhash: double-ohio-glucose-lake
File name:m87.dll
Download: download sample
Signature TrickBot
File size:923'136 bytes
First seen:2021-02-26 21:56:10 UTC
Last seen:2021-02-26 23:10:07 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 0603e55f4c0e9286ec51b1773493a9be (2 x TrickBot)
ssdeep 12288:HC6mAaWJEKLdMa/WBX73zAWqayjTrW7PgYPzWbKjl9qUWu4DqA4lXHnp+APAhx:HMAlpyNAj+LbrjlNlXHn6x
Threatray 7 similar samples on MalwareBazaar
TLSH F015B10359DCBCADC03D8130233BE7E58B2FDC1D0662C69B62C6EA65A53CD4B71A2795
Reporter Cryptolaemus1
Tags:dll TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
232
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 359099 Sample: m87.dll Startdate: 26/02/2021 Architecture: WINDOWS Score: 56 30 Antivirus / Scanner detection for submitted sample 2->30 32 Multi AV Scanner detection for submitted file 2->32 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 regsvr32.exe 8->12         started        14 rundll32.exe 8->14         started        process5 16 iexplore.exe 2 84 10->16         started        dnsIp6 22 192.168.2.1 unknown unknown 16->22 19 iexplore.exe 5 160 16->19         started        process7 dnsIp8 24 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49743, 49744 FASTLYUS United States 19->24 26 geolocation.onetrust.com 104.20.184.68, 443, 49728, 49729 CLOUDFLARENETUS United States 19->26 28 8 other IPs or domains 19->28
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-02-26 19:20:43 UTC
AV detection:
11 of 29 (37.93%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:mon87 banker trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
41.77.134.250:449
45.155.173.242:443
192.162.238.186:449
142.112.79.223:449
122.2.28.70:449
154.126.176.30:449
45.230.244.20:443
182.253.107.34:443
200.52.147.93:443
123.200.26.246:449
131.255.106.152:449
177.85.133.118:449
103.225.138.94:449
142.202.191.164:443
95.210.118.90:449
36.94.62.207:443
201.20.118.122:449
180.92.238.186:449
103.130.6.244:449
202.91.41.138:449
187.20.217.129:449
Unpacked files
SH256 hash:
a9ac7e8a78c813e5fd42ba2b1a44b2c9466b498c9ff82538426f34e6ada4b132
MD5 hash:
35c9d39c6fd726f70182756467f3bff0
SHA1 hash:
279343cc1637a5b014dc64892cce66b66fe01209
Detections:
win_trickbot_a4 win_trickbot_auto
SH256 hash:
e17b041a74d30ef6ae3569c89d8c282f02008abf6b43f237f75dba42d378a8f3
MD5 hash:
b5e31902cfa70203fa2b4a00a6f0a6ea
SHA1 hash:
4795975325269953f39848600e641be97e0c1ebc
SH256 hash:
36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98
MD5 hash:
d48404abfb5c8a7bac7f9f619da899e9
SHA1 hash:
05acc14a076af1e2696faa5fa4e32778e55ec27f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll 36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98

(this sample)

  
Delivery method
Distributed via web download

Comments