MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 58cdbb2c17ea6d6eb5a1c6952a8c6bf9e918c51bfc58a2639d2cf031b359da06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 8
| SHA256 hash: | 58cdbb2c17ea6d6eb5a1c6952a8c6bf9e918c51bfc58a2639d2cf031b359da06 |
|---|---|
| SHA3-384 hash: | f41828a1a8c50e266f722e14b8929311ead4b492a5155c9737b14bae469d12da9852a13d4bb4426d50c95543fdf04c41 |
| SHA1 hash: | b321f66d1a06ef9883ca06d78e0f0b2dd1705c93 |
| MD5 hash: | ac11833ad6b6b6b894c8afc1bcb68140 |
| humanhash: | yankee-kitten-florida-fish |
| File name: | ac11833ad6b6b6b894c8afc1bcb68140.dll |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 361'472 bytes |
| First seen: | 2021-02-15 20:15:20 UTC |
| Last seen: | 2021-02-15 21:49:49 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | ee693e3bb4d5864fb5995225a53cea3c (3 x TrickBot) |
| ssdeep | 6144:MvcW/D6HvoYb988GdTIKEXv/ZwHxIdfrYOxO6c8PCJV:M0E6Po498tTlEHZwRaYoO6uJV |
| TLSH | C5747C00B571051DD7AA43B314ADBEC29A3866887F7CCB5F666E08DF5728933710FA92 |
| Reporter | |
| Tags: | dll mon57 TrickBot |
Intelligence
File Origin
# of uploads :
2
# of downloads :
182
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Result
Verdict:
Clean
Maliciousness:
Behaviour
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Detection:
trickbot
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-02-15 20:16:08 UTC
AV detection:
10 of 29 (34.48%)
Threat level:
5/5
Detection(s):
Malicious file
Verdict:
unknown
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:mon57 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
194.5.249.156:443
142.202.191.164:443
193.8.194.96:443
45.155.173.242:443
108.170.20.75:443
185.163.45.138:443
94.140.114.136:443
134.119.186.202:443
200.52.147.93:443
45.230.244.20:443
186.250.157.116:443
186.137.85.76:443
36.94.62.207:443
182.253.107.34:443
142.202.191.164:443
193.8.194.96:443
45.155.173.242:443
108.170.20.75:443
185.163.45.138:443
94.140.114.136:443
134.119.186.202:443
200.52.147.93:443
45.230.244.20:443
186.250.157.116:443
186.137.85.76:443
36.94.62.207:443
182.253.107.34:443
Unpacked files
SH256 hash:
60c9dc37c613f9db6184f3cb0671ec5adf66f5adac682f455c08a1440865da11
MD5 hash:
e7261dce4178d7a90c829fcea5aa89f8
SHA1 hash:
ca7d87c8a4ebe2652efdcbb448b5540f8d93f7f2
SH256 hash:
37b7f675a9f9fee97bb4a16d624496019c8300f993def1c967d70fc64f8651f0
MD5 hash:
077f44df521f03b0d264bca595112c44
SHA1 hash:
860a1ddce2938fa30cd98dc8d7519ea299138402
Detections:
win_trickbot_a4
win_trickbot_auto
SH256 hash:
58cdbb2c17ea6d6eb5a1c6952a8c6bf9e918c51bfc58a2639d2cf031b359da06
MD5 hash:
ac11833ad6b6b6b894c8afc1bcb68140
SHA1 hash:
b321f66d1a06ef9883ca06d78e0f0b2dd1705c93
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.