🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 37ff98395d4db062f03fdd648bbcc47f7aa0db3afa3bbc5ed44f308cf50499d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 37ff98395d4db062f03fdd648bbcc47f7aa0db3afa3bbc5ed44f308cf50499d0
SHA3-384 hash: 202dd1d0fc8fc0d2a213c11fc5530c7856ff4e8207be7690e09598f9b1cfb6da3630e4e874081ed972011b37486f27ec
SHA1 hash: d9005790ec907da4536f74e7229fe6f7318e3373
MD5 hash: 4328f83690bea146835b8a62ab321e3c
humanhash: papa-wyoming-blue-november
File name:37ff98395d4db062f03fdd648bbcc47f7aa0db3afa3bbc5ed44f308cf50499d0-1
Download: download sample
Signature TrickBot
File size:2'426'586 bytes
First seen:2022-12-20 15:30:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash be41bf7b8cc010b614bd36bbca606973 (195 x LummaStealer, 126 x DanaBot, 63 x Vidar)
ssdeep 49152:6M+mmTGRHhVKvDxVELMQ37INHRFXz86RJobbUWhI9mMK:vxH8D/VHX/JCbBSmMK
TLSH T171B533427A2C41FEE68309733A39CCC256066E225D67528E9341BDCC677779BEA08773
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 71cc92a2aa96cc71 (1 x TrickBot)
Reporter DesdinovaOsint
Tags:exe TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
641
Origin country :
PT PT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
37ff98395d4db062f03fdd648bbcc47f7aa0db3afa3bbc5ed44f308cf50499d0-1
Verdict:
Malicious activity
Analysis date:
2022-12-20 15:31:37 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Creating a file
Creating a file in the Program Files subdirectories
Creating a file in the drivers directory
Creating a service
Launching a service
Loading a system driver
Modifying a system file
Creating a file in the Windows subdirectories
Searching for synchronization primitives
Launching a process
Sending a UDP request
Query of malicious DNS domain
Enabling autorun for a service
Gathering data
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes security center settings (notifications, updates, antivirus, firewall)
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to infect the boot sector
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Query firmware table information (likely to detect VMs)
Sample is not signed and drops a device driver
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Winsecsrv
Status:
Malicious
First seen:
2019-05-24 13:31:16 UTC
File Type:
PE (Exe)
Extracted files:
41
AV detection:
27 of 41 (65.85%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
trickbot
Result
Malware family:
n/a
Score:
  9/10
Tags:
bootkit discovery persistence upx
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Enumerates physical storage devices
Drops file in Program Files directory
Checks installed software on the system
Maps connected drives based on registry
Writes to the Master Boot Record (MBR)
Loads dropped DLL
Drops file in Drivers directory
Sets service image path in registry
UPX packed file
ACProtect 1.3x - 1.4x DLL software
Unpacked files
SH256 hash:
f83f364587c83d72986244db4a1918158cff46ab552c7afb5da5a222dbaeba63
MD5 hash:
ddc3632b743d4e6a52407f83f722be87
SHA1 hash:
4aaab3b8473dc31ebd2759f0e466c7f4b6b13138
SH256 hash:
f069ad23f91b65510453711d0d7870dc4528d97b2351cf240ef190fef6b18c63
MD5 hash:
ca73a16a4234c05d9dfd67f2645de920
SHA1 hash:
c3856ed743c4886b7ae6e2b2632c89790cf6113c
SH256 hash:
26135efe70d2e102b1d3f67109877b355af75cf9f40867ad10c8d16d8a02ff78
MD5 hash:
c0de347aa8bca1b70f51d1f9bfe19a12
SHA1 hash:
0ca9010965a9aba7438b12bde67c05c82c1afe92
SH256 hash:
f0e14bee1e8c16f7565ba88ebaf42cbd8f1eeb209c44762f345109befbce4c2e
MD5 hash:
5f023782541d23e52d2d0e274d00b50a
SHA1 hash:
c9eb8a528953367e7bac9aaf41354f73e407cac5
SH256 hash:
7851cb12fa4131f1fee5de390d650ef65cac561279f1cfe70ad16cc9780210af
MD5 hash:
bf712f32249029466fa86756f5546950
SHA1 hash:
75ac4dc4808ac148ddd78f6b89a51afbd4091c2e
SH256 hash:
37ff98395d4db062f03fdd648bbcc47f7aa0db3afa3bbc5ed44f308cf50499d0
MD5 hash:
4328f83690bea146835b8a62ab321e3c
SHA1 hash:
d9005790ec907da4536f74e7229fe6f7318e3373
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments