MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5271f69c2c7ba291d588b7dcc371f72a117c0a7f3c2fe86676d6d2a8822e529c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 10
| SHA256 hash: | 5271f69c2c7ba291d588b7dcc371f72a117c0a7f3c2fe86676d6d2a8822e529c |
|---|---|
| SHA3-384 hash: | 32fff006998840e3e3829ddb8eb01489fe2c55482be185188691084b22536e467f25ae21d310e532aed3b41abf48c716 |
| SHA1 hash: | 1a66dc68510e10ce83ce0c938c185bf67cf0eb44 |
| MD5 hash: | ba820cf3ca3957bd6401fc39b8d692b9 |
| humanhash: | crazy-happy-maryland-red |
| File name: | ba820cf3_by_Libranalysis |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 547'608 bytes |
| First seen: | 2021-05-04 10:02:23 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | ea97e91275f65096e0769ec8f21f572b (18 x TrickBot) |
| ssdeep | 12288:Zx1Q61iHsXYvfVpMODDawkCurdEtttYW60EQSO1A:ZXQUIsQpMsequrmGh |
| Threatray | 3'213 similar samples on MalwareBazaar |
| TLSH | D7C4E02A37E1CCB7C5A755790EE2DBAA62FAFD204F718A8323543B0D4E31AD15931316 |
| Reporter | |
| Tags: | TrickBot |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
172.245.97.148:443
85.204.116.139:443
185.62.188.117:443
185.222.202.76:443
144.91.79.12:443
185.68.93.43:443
195.123.238.191:443
146.185.219.29:443
195.133.196.151:443
91.235.129.60:443
23.227.206.170:443
185.222.202.192:443
190.154.203.218:449
178.183.150.169:449
200.116.199.10:449
187.58.56.26:449
177.103.240.149:449
81.190.160.139:449
200.21.51.38:449
181.49.61.237:449
46.174.235.36:449
36.89.85.103:449
170.233.120.53:449
89.228.243.148:449
31.214.138.207:449
186.42.98.254:449
195.93.223.100:449
181.112.52.26:449
190.13.160.19:449
186.71.150.23:449
190.152.4.98:449
170.82.156.53:449
131.161.253.190:449
200.127.121.99:449
45.235.213.126:449
31.128.13.45:449
181.10.207.234:449
201.187.105.123:449
201.210.120.239:449
190.152.125.22:449
103.69.216.86:449
128.201.174.107:449
101.108.92.111:449
190.111.255.219:449
Unpacked files
7ddc410b3d455415f58ab98ded230a9bd9617c7c894588475e3b003cbf904754
a305fedc0b76bc6a36c92b06664f96a3a85f3784c1b8a272f00bce9f623fc9e8
fe6536af67f91c583d23236ccd090fce698b2f875e5906a0d2dd30d2a59072cf
065632e06e556d26314865646f6fdb70585e3ee1a96336f8ae1787da420c0dfb
a19896b2206755083b9881636def83c36555331f4e4976602eb5944ce15917c5
d6b893f5ddab88602eb6d5b6ac200b709f53ba72dc9310680d7b0262ac67eede
34aba4b668b4f82e6fce7f6fc02c1d1c82a0352692979604d145f38ab2bd3433
7e29d464e336d904d8aee54edf8b499c4095c3659a8b202218903f071239d983
d2122f044167ecb831d202ce7829d2e50a902266f7e290e42b5ff432e8879b9a
9754089f79d9c9293dcc9c604c6328284a7942539a46c13112558a39c92a5e41
e9c98bff81ba5138f040cef7acbcb56f0f80abcf41ecf4893d4700e308f6427a
5271f69c2c7ba291d588b7dcc371f72a117c0a7f3c2fe86676d6d2a8822e529c
9fdea40a9872a77335ae3b733a50f4d1e9f8eff193ae84e36fb7e5802c481f72
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | Cobalt_functions |
|---|---|
| Author: | @j0sm1 |
| Description: | Detect functions coded with ROR edi,D; Detect CobaltStrike used by differents groups APT |
| Rule name: | IceID_Bank_trojan |
|---|---|
| Author: | unixfreaxjp |
| Description: | Detects IcedID..adjusted several times |
| Rule name: | win_trickbot_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | autogenerated rule brought to you by yara-signator |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
1) [C0049] File System Micro-objective::Get File Attributes
2) [C0051] File System Micro-objective::Read File
3) [C0052] File System Micro-objective::Writes File
4) [C0034.001] Operating System Micro-objective::Set Variable::Environment Variable
5) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
6) [C0036.002] Operating System Micro-objective::Delete Registry Key::Registry
7) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
8) [C0036.005] Operating System Micro-objective::Query Registry Key::Registry
9) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
10) [C0036.001] Operating System Micro-objective::Set Registry Key::Registry
11) [C0040] Process Micro-objective::Allocate Thread Local Storage
12) [C0041] Process Micro-objective::Set Thread Local Storage Value
13) [C0018] Process Micro-objective::Terminate Process