MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 487f4dd9bdbe94a9cf1a04a8fdec19f16f86864d05d06f0511544b3ff68c850c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 4
| SHA256 hash: | 487f4dd9bdbe94a9cf1a04a8fdec19f16f86864d05d06f0511544b3ff68c850c |
|---|---|
| SHA3-384 hash: | 4ad6b325e7e2420b324f52ee4ac1b4be563a94557d5716bceb668f367c720b0bf95d2ca34611836d277618de9b598306 |
| SHA1 hash: | da193bad12f1b79f8c938d62e8029ba948433859 |
| MD5 hash: | d8e816c76ab1b9bc76e73b1aa0f88f2d |
| humanhash: | nitrogen-magnesium-nitrogen-seven |
| File name: | malware_samples.zip |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 19'987'747 bytes |
| First seen: | 2025-04-07 04:19:55 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| Note: | This file is a password protected archive. The password is: infected |
| ssdeep | 393216:ThCblxXJLB2mW/RxHedw0OZnq0NyWl9Hh9H2KAm4zI:ThSDZLI5xHea9Zf5XHD4zI |
| TLSH | T12B17339590E4E71AC422E5A3E4F5E7C94FB461B988344CCA6DB45FE3A0A30FC3BD6419 |
| Magika | zip |
| Reporter | |
| Tags: | bad Emotet Heodo TrickBot zip |
Intelligence
File Origin
IDFile Archive Information
This file archive contains 19 file(s), sorted by their relevance:
| File name: | VirusShare_0fea640a7da27f365b3675f73626b9c9 |
|---|---|
| File size: | 960'000 bytes |
| SHA256 hash: | 64af94592f6707505fa6f42b58776c3635706a414e6362a92f707df84627679c |
| MD5 hash: | 0fea640a7da27f365b3675f73626b9c9 |
| MIME type: | application/vnd.ms-excel |
| Signature | TrickBot |
| File name: | VirusShare_3cd9a967b67fe69351e390195ca7a430 |
|---|---|
| File size: | 32'923 bytes |
| SHA256 hash: | e96e3b90d9483a2e463fdda0edf27310ed10fbdb8a8b920c6480ca93bb2e1077 |
| MD5 hash: | 3cd9a967b67fe69351e390195ca7a430 |
| MIME type: | application/pdf |
| Signature | TrickBot |
| File name: | VirusShare_4aa5734fe9c86184f931f4ddaf2d4d7b |
|---|---|
| File size: | 65'536 bytes |
| SHA256 hash: | 2e18ad3e470b97415beb2cdb8e3ef7510bad21f0a5add020a7f9343dd959eeaa |
| MD5 hash: | 4aa5734fe9c86184f931f4ddaf2d4d7b |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
| File name: | VirusShare_4675e87be15585e66b0c88b833dd9ecd |
|---|---|
| File size: | 32'800 bytes |
| SHA256 hash: | 77e2bcef8ff0e68646b27591faea3e15b4a09154d0611a5004ec028df5f36256 |
| MD5 hash: | 4675e87be15585e66b0c88b833dd9ecd |
| MIME type: | application/pdf |
| Signature | TrickBot |
| File name: | VirusShare_6ad036ba93c94d6976e2d93c7a3aec6f |
|---|---|
| File size: | 176'290 bytes |
| SHA256 hash: | 4ee0bf78e3b0a06c35fed0f912db6fabbb5fae13f838cd4132634359ad0d24da |
| MD5 hash: | 6ad036ba93c94d6976e2d93c7a3aec6f |
| MIME type: | application/msword |
| Signature | TrickBot |
| File name: | VirusShare_3f0b1eed4b7b9ae05fab4d949843f103 |
|---|---|
| File size: | 35'840 bytes |
| SHA256 hash: | ce21d34bafe338effb8f619936f057084cb45743fce884a1465966d8523a00a8 |
| MD5 hash: | 3f0b1eed4b7b9ae05fab4d949843f103 |
| MIME type: | application/CDFV2 |
| Signature | TrickBot |
| File name: | VirusShare_0aee78510c46e3a200b6bc21ac1c954d |
|---|---|
| File size: | 648'320 bytes |
| SHA256 hash: | c7d63abc749b1f4e245bd377c11ca5857735491eddab5c176ae99a3b7bf9e0ca |
| MD5 hash: | 0aee78510c46e3a200b6bc21ac1c954d |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
| File name: | VirusShare_1ad9a67240d5775395c45b64dd6529fa |
|---|---|
| File size: | 3'074'448 bytes |
| SHA256 hash: | 3751298058a2a5d0912caa35bfdbafa48ae788647b536e69ad383c7c1990dd9d |
| MD5 hash: | 1ad9a67240d5775395c45b64dd6529fa |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
| File name: | VirusShare_3fb34964fa7b8c6bfad8d960380ff04e |
|---|---|
| File size: | 35'328 bytes |
| SHA256 hash: | 26026b1b3d0cb660c6be6c536df679acca0b5562a3adbb507d001474d23f5650 |
| MD5 hash: | 3fb34964fa7b8c6bfad8d960380ff04e |
| MIME type: | application/CDFV2 |
| Signature | TrickBot |
| File name: | wedding.apk |
|---|---|
| File size: | 5'551'757 bytes |
| SHA256 hash: | 7a42d7809fdef76fe0580d09ef6780a96c000d97712236e6550d7fff061e122a |
| MD5 hash: | 7a78191dad2e8baf6b372a4dc864430c |
| MIME type: | application/zip |
| Signature | TrickBot |
| File name: | VirusShare_0a2d1ecedf3f79754aa2c18d62e75287 |
|---|---|
| File size: | 5'968'633 bytes |
| SHA256 hash: | e800fce6aadc7792b912abbb693aafe0905a5ab52bc92de9e2a50089de312be9 |
| MD5 hash: | 0a2d1ecedf3f79754aa2c18d62e75287 |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
| File name: | VirusShare_2fe5b00079aec2d8369a798230313ec8 |
|---|---|
| File size: | 128'743 bytes |
| SHA256 hash: | 8eb6805a0852b220695175ce81a5b139f1438dc06ea3fc1347b047702880374c |
| MD5 hash: | 2fe5b00079aec2d8369a798230313ec8 |
| MIME type: | application/msword |
| Signature | Heodo |
| File name: | delivery.apk |
|---|---|
| File size: | 5'522'263 bytes |
| SHA256 hash: | 1cb93604fc99d47c24e7c6db6c6286ad40a4c2edf079612b5b1d3b9b91b65c1e |
| MD5 hash: | 87692d3c410fcc2d6c77258bef05690b |
| MIME type: | application/zip |
| Signature | TrickBot |
| File name: | VirusShare_6d2d7d94fe5faab76b3e786e7d810c1d |
|---|---|
| File size: | 2'391'870 bytes |
| SHA256 hash: | 3085c886924395409bd3e1cd673e463001f9ff9aedf829de843b462f8138cb0a |
| MD5 hash: | b66689ebd2ec53c0035ac39262343ab4 |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
| File name: | VirusShare_4b8eb7fe75f72c1c5c1f80af9cd165d2 |
|---|---|
| File size: | 65'536 bytes |
| SHA256 hash: | 55dd85b37566755ea1ffb022030b413d2722120067abd9b298a89a61f4b790c2 |
| MD5 hash: | 4b8eb7fe75f72c1c5c1f80af9cd165d2 |
| MIME type: | application/CDFV2 |
| Signature | TrickBot |
| File name: | VirusShare_1ba8249d8503c0cf7bc125588c43bef9 |
|---|---|
| File size: | 187'239 bytes |
| SHA256 hash: | a44031feb2a71980a0980377c8f7b6f3b5b9dfa0f708556dd420be323c7e1a38 |
| MD5 hash: | 1ba8249d8503c0cf7bc125588c43bef9 |
| MIME type: | application/msword |
| Signature | Heodo |
| File name: | VirusShare_480ef02bb062a57724e1b3e14532a140 |
|---|---|
| File size: | 33'611 bytes |
| SHA256 hash: | b2e302356d613a814a41d356a61cee24fc133dd032e4b02d8e29436aedd8d742 |
| MD5 hash: | 480ef02bb062a57724e1b3e14532a140 |
| MIME type: | application/pdf |
| Signature | TrickBot |
| File name: | VirusShare_01b55404de50bd1a56343b2f316ff88d |
|---|---|
| File size: | 123'904 bytes |
| SHA256 hash: | 69bd652ace6469311a49a12f66bbbc691bdfc69aba958dd02d928464cbb46609 |
| MD5 hash: | 01b55404de50bd1a56343b2f316ff88d |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
| File name: | VirusShare_5c8b670c503455baafbff400a446cf82 |
|---|---|
| File size: | 212'992 bytes |
| SHA256 hash: | 22564368a2143231eb51f0ecb501d9777060fd9dd832dcc88a799520884da40c |
| MD5 hash: | 5c8b670c503455baafbff400a446cf82 |
| MIME type: | application/x-dosexec |
| Signature | TrickBot |
Vendor Threat Intelligence
Result
Malware Config
http://ns8.softline.top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
http://ns9.softline.top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
5.182.210.226:443
5.182.210.120:443
185.65.202.183:443
212.80.217.243:443
85.143.218.249:443
194.5.250.178:443
198.15.119.121:443
107.175.87.142:443
185.14.31.72:443
188.165.62.2:443
194.5.250.179:443
198.15.119.71:443
185.14.29.4:443
185.99.2.202:443
192.3.193.162:443
89.191.234.89:443
195.54.32.12:443
31.131.21.30:443
5.34.177.194:443
190.214.13.2:449
181.140.173.186:449
181.129.104.139:449
181.113.28.146:449
181.112.157.42:449
170.84.78.224:449
200.21.51.38:449
46.174.235.36:449
36.89.85.103:449
181.129.134.18:449
186.71.150.23:449
131.161.253.190:449
200.127.121.99:449
114.8.133.71:449
119.252.165.75:449
121.100.19.18:449
202.29.215.114:449
180.180.216.177:449
171.100.142.238:449
186.232.91.240:449
181.196.207.202:449
https://eficadgdl.com/well/Omitted-Credentials_encrypted_6A17930.bin
https://www.silvesterinmailand.com/wp-content/uploads/ibvgux-yg4-03475/
http://homemyland.net/tmp/wUHdeBS/
https://www.celbra.com.br/old/wp-content/uploads/2019/mbwl6-lwu0psmcb-523/
http://prihlaska.sagitta.cz/wp-content/uploads/WwcQXtRta/
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | SharedStrings |
|---|---|
| Author: | Katie Kleemola |
| Description: | Internal names found in LURK0/CCTV0 samples |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | win_alina_pos_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | autogenerated rule brought to you by yara-signator |
| Rule name: | win_gootkit_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | autogenerated rule brought to you by yara-signator |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.