MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 10
| SHA256 hash: | 36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98 |
|---|---|
| SHA3-384 hash: | 595f20594c7cff4ae86fce9f2f95e107d96c8c7bbc6676555849430703d3d7014ec5933988288e13cda3580eb8d1b136 |
| SHA1 hash: | 05acc14a076af1e2696faa5fa4e32778e55ec27f |
| MD5 hash: | d48404abfb5c8a7bac7f9f619da899e9 |
| humanhash: | double-ohio-glucose-lake |
| File name: | m87.dll |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 923'136 bytes |
| First seen: | 2021-02-26 21:56:10 UTC |
| Last seen: | 2021-02-26 23:10:07 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 0603e55f4c0e9286ec51b1773493a9be (2 x TrickBot) |
| ssdeep | 12288:HC6mAaWJEKLdMa/WBX73zAWqayjTrW7PgYPzWbKjl9qUWu4DqA4lXHnp+APAhx:HMAlpyNAj+LbrjlNlXHn6x |
| Threatray | 7 similar samples on MalwareBazaar |
| TLSH | F015B10359DCBCADC03D8130233BE7E58B2FDC1D0662C69B62C6EA65A53CD4B71A2795 |
| Reporter | |
| Tags: | dll TrickBot |
Intelligence
File Origin
# of uploads :
2
# of downloads :
232
Origin country :
n/a
Vendor Threat Intelligence
Detection:
TrickBot
Detection(s):
Result
Verdict:
Malware
Maliciousness:
Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Detection:
trickbot
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-02-26 19:20:43 UTC
AV detection:
11 of 29 (37.93%)
Threat level:
5/5
Detection(s):
Malicious file
Verdict:
unknown
Similar samples:
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:mon87 banker trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
41.77.134.250:449
45.155.173.242:443
192.162.238.186:449
142.112.79.223:449
122.2.28.70:449
154.126.176.30:449
45.230.244.20:443
182.253.107.34:443
200.52.147.93:443
123.200.26.246:449
131.255.106.152:449
177.85.133.118:449
103.225.138.94:449
142.202.191.164:443
95.210.118.90:449
36.94.62.207:443
201.20.118.122:449
180.92.238.186:449
103.130.6.244:449
202.91.41.138:449
187.20.217.129:449
45.155.173.242:443
192.162.238.186:449
142.112.79.223:449
122.2.28.70:449
154.126.176.30:449
45.230.244.20:443
182.253.107.34:443
200.52.147.93:443
123.200.26.246:449
131.255.106.152:449
177.85.133.118:449
103.225.138.94:449
142.202.191.164:443
95.210.118.90:449
36.94.62.207:443
201.20.118.122:449
180.92.238.186:449
103.130.6.244:449
202.91.41.138:449
187.20.217.129:449
Unpacked files
SH256 hash:
a9ac7e8a78c813e5fd42ba2b1a44b2c9466b498c9ff82538426f34e6ada4b132
MD5 hash:
35c9d39c6fd726f70182756467f3bff0
SHA1 hash:
279343cc1637a5b014dc64892cce66b66fe01209
Detections:
win_trickbot_a4
win_trickbot_auto
SH256 hash:
e17b041a74d30ef6ae3569c89d8c282f02008abf6b43f237f75dba42d378a8f3
MD5 hash:
b5e31902cfa70203fa2b4a00a6f0a6ea
SHA1 hash:
4795975325269953f39848600e641be97e0c1ebc
SH256 hash:
36a3edc08009fefa694124a1b09f45657496f8a1e6c0c009093f134632c27e98
MD5 hash:
d48404abfb5c8a7bac7f9f619da899e9
SHA1 hash:
05acc14a076af1e2696faa5fa4e32778e55ec27f
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.