🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 487f4dd9bdbe94a9cf1a04a8fdec19f16f86864d05d06f0511544b3ff68c850c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments

SHA256 hash: 487f4dd9bdbe94a9cf1a04a8fdec19f16f86864d05d06f0511544b3ff68c850c
SHA3-384 hash: 4ad6b325e7e2420b324f52ee4ac1b4be563a94557d5716bceb668f367c720b0bf95d2ca34611836d277618de9b598306
SHA1 hash: da193bad12f1b79f8c938d62e8029ba948433859
MD5 hash: d8e816c76ab1b9bc76e73b1aa0f88f2d
humanhash: nitrogen-magnesium-nitrogen-seven
File name:malware_samples.zip
Download: download sample
Signature TrickBot
File size:19'987'747 bytes
First seen:2025-04-07 04:19:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 393216:ThCblxXJLB2mW/RxHedw0OZnq0NyWl9Hh9H2KAm4zI:ThSDZLI5xHea9Zf5XHD4zI
TLSH T12B17339590E4E71AC422E5A3E4F5E7C94FB461B988344CCA6DB45FE3A0A30FC3BD6419
Magika zip
Reporter Hares
Tags:bad Emotet Heodo TrickBot zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
2'067
Origin country :
ID ID
File Archive Information

This file archive contains 19 file(s), sorted by their relevance:

File name:VirusShare_0fea640a7da27f365b3675f73626b9c9
File size:960'000 bytes
SHA256 hash: 64af94592f6707505fa6f42b58776c3635706a414e6362a92f707df84627679c
MD5 hash: 0fea640a7da27f365b3675f73626b9c9
MIME type:application/vnd.ms-excel
Signature TrickBot
File name:VirusShare_3cd9a967b67fe69351e390195ca7a430
File size:32'923 bytes
SHA256 hash: e96e3b90d9483a2e463fdda0edf27310ed10fbdb8a8b920c6480ca93bb2e1077
MD5 hash: 3cd9a967b67fe69351e390195ca7a430
MIME type:application/pdf
Signature TrickBot
File name:VirusShare_4aa5734fe9c86184f931f4ddaf2d4d7b
File size:65'536 bytes
SHA256 hash: 2e18ad3e470b97415beb2cdb8e3ef7510bad21f0a5add020a7f9343dd959eeaa
MD5 hash: 4aa5734fe9c86184f931f4ddaf2d4d7b
MIME type:application/x-dosexec
Signature TrickBot
File name:VirusShare_4675e87be15585e66b0c88b833dd9ecd
File size:32'800 bytes
SHA256 hash: 77e2bcef8ff0e68646b27591faea3e15b4a09154d0611a5004ec028df5f36256
MD5 hash: 4675e87be15585e66b0c88b833dd9ecd
MIME type:application/pdf
Signature TrickBot
File name:VirusShare_6ad036ba93c94d6976e2d93c7a3aec6f
File size:176'290 bytes
SHA256 hash: 4ee0bf78e3b0a06c35fed0f912db6fabbb5fae13f838cd4132634359ad0d24da
MD5 hash: 6ad036ba93c94d6976e2d93c7a3aec6f
MIME type:application/msword
Signature TrickBot
File name:VirusShare_3f0b1eed4b7b9ae05fab4d949843f103
File size:35'840 bytes
SHA256 hash: ce21d34bafe338effb8f619936f057084cb45743fce884a1465966d8523a00a8
MD5 hash: 3f0b1eed4b7b9ae05fab4d949843f103
MIME type:application/CDFV2
Signature TrickBot
File name:VirusShare_0aee78510c46e3a200b6bc21ac1c954d
File size:648'320 bytes
SHA256 hash: c7d63abc749b1f4e245bd377c11ca5857735491eddab5c176ae99a3b7bf9e0ca
MD5 hash: 0aee78510c46e3a200b6bc21ac1c954d
MIME type:application/x-dosexec
Signature TrickBot
File name:VirusShare_1ad9a67240d5775395c45b64dd6529fa
File size:3'074'448 bytes
SHA256 hash: 3751298058a2a5d0912caa35bfdbafa48ae788647b536e69ad383c7c1990dd9d
MD5 hash: 1ad9a67240d5775395c45b64dd6529fa
MIME type:application/x-dosexec
Signature TrickBot
File name:VirusShare_3fb34964fa7b8c6bfad8d960380ff04e
File size:35'328 bytes
SHA256 hash: 26026b1b3d0cb660c6be6c536df679acca0b5562a3adbb507d001474d23f5650
MD5 hash: 3fb34964fa7b8c6bfad8d960380ff04e
MIME type:application/CDFV2
Signature TrickBot
File name:wedding.apk
File size:5'551'757 bytes
SHA256 hash: 7a42d7809fdef76fe0580d09ef6780a96c000d97712236e6550d7fff061e122a
MD5 hash: 7a78191dad2e8baf6b372a4dc864430c
MIME type:application/zip
Signature TrickBot
File name:VirusShare_0a2d1ecedf3f79754aa2c18d62e75287
File size:5'968'633 bytes
SHA256 hash: e800fce6aadc7792b912abbb693aafe0905a5ab52bc92de9e2a50089de312be9
MD5 hash: 0a2d1ecedf3f79754aa2c18d62e75287
MIME type:application/x-dosexec
Signature TrickBot
File name:VirusShare_2fe5b00079aec2d8369a798230313ec8
File size:128'743 bytes
SHA256 hash: 8eb6805a0852b220695175ce81a5b139f1438dc06ea3fc1347b047702880374c
MD5 hash: 2fe5b00079aec2d8369a798230313ec8
MIME type:application/msword
Signature Heodo
File name:delivery.apk
File size:5'522'263 bytes
SHA256 hash: 1cb93604fc99d47c24e7c6db6c6286ad40a4c2edf079612b5b1d3b9b91b65c1e
MD5 hash: 87692d3c410fcc2d6c77258bef05690b
MIME type:application/zip
Signature TrickBot
File name:VirusShare_6d2d7d94fe5faab76b3e786e7d810c1d
File size:2'391'870 bytes
SHA256 hash: 3085c886924395409bd3e1cd673e463001f9ff9aedf829de843b462f8138cb0a
MD5 hash: b66689ebd2ec53c0035ac39262343ab4
MIME type:application/x-dosexec
Signature TrickBot
File name:VirusShare_4b8eb7fe75f72c1c5c1f80af9cd165d2
File size:65'536 bytes
SHA256 hash: 55dd85b37566755ea1ffb022030b413d2722120067abd9b298a89a61f4b790c2
MD5 hash: 4b8eb7fe75f72c1c5c1f80af9cd165d2
MIME type:application/CDFV2
Signature TrickBot
File name:VirusShare_1ba8249d8503c0cf7bc125588c43bef9
File size:187'239 bytes
SHA256 hash: a44031feb2a71980a0980377c8f7b6f3b5b9dfa0f708556dd420be323c7e1a38
MD5 hash: 1ba8249d8503c0cf7bc125588c43bef9
MIME type:application/msword
Signature Heodo
File name:VirusShare_480ef02bb062a57724e1b3e14532a140
File size:33'611 bytes
SHA256 hash: b2e302356d613a814a41d356a61cee24fc133dd032e4b02d8e29436aedd8d742
MD5 hash: 480ef02bb062a57724e1b3e14532a140
MIME type:application/pdf
Signature TrickBot
File name:VirusShare_01b55404de50bd1a56343b2f316ff88d
File size:123'904 bytes
SHA256 hash: 69bd652ace6469311a49a12f66bbbc691bdfc69aba958dd02d928464cbb46609
MD5 hash: 01b55404de50bd1a56343b2f316ff88d
MIME type:application/x-dosexec
Signature TrickBot
File name:VirusShare_5c8b670c503455baafbff400a446cf82
File size:212'992 bytes
SHA256 hash: 22564368a2143231eb51f0ecb501d9777060fd9dd832dcc88a799520884da40c
MD5 hash: 5c8b670c503455baafbff400a446cf82
MIME type:application/x-dosexec
Signature TrickBot
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
microsoft_visual_cc overlay packed
Result
Malware family:
Score:
  10/10
Tags:
family:cobaltstrike family:guloader family:ta505 family:trickbot family:xmrig botnet:0 botnet:ono33 android discovery downloader execution link macro macro_on_action miner pdf persistence upx
Malware Config
C2 Extraction:
http://ns7.softline.top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
http://ns8.softline.top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
http://ns9.softline.top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
5.182.210.226:443
5.182.210.120:443
185.65.202.183:443
212.80.217.243:443
85.143.218.249:443
194.5.250.178:443
198.15.119.121:443
107.175.87.142:443
185.14.31.72:443
188.165.62.2:443
194.5.250.179:443
198.15.119.71:443
185.14.29.4:443
185.99.2.202:443
192.3.193.162:443
89.191.234.89:443
195.54.32.12:443
31.131.21.30:443
5.34.177.194:443
190.214.13.2:449
181.140.173.186:449
181.129.104.139:449
181.113.28.146:449
181.112.157.42:449
170.84.78.224:449
200.21.51.38:449
46.174.235.36:449
36.89.85.103:449
181.129.134.18:449
186.71.150.23:449
131.161.253.190:449
200.127.121.99:449
114.8.133.71:449
119.252.165.75:449
121.100.19.18:449
202.29.215.114:449
180.180.216.177:449
171.100.142.238:449
186.232.91.240:449
181.196.207.202:449
https://eficadgdl.com/well/Omitted-Credentials_encrypted_6A17930.bin
Dropper Extraction:
http://www.prorites.com/wp-content/dsdb28de-kw0ch1msvi-003/
https://www.silvesterinmailand.com/wp-content/uploads/ibvgux-yg4-03475/
http://homemyland.net/tmp/wUHdeBS/
https://www.celbra.com.br/old/wp-content/uploads/2019/mbwl6-lwu0psmcb-523/
http://prihlaska.sagitta.cz/wp-content/uploads/WwcQXtRta/
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SharedStrings
Author:Katie Kleemola
Description:Internal names found in LURK0/CCTV0 samples
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:win_alina_pos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator
Rule name:win_gootkit_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments