🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71b2c64ccc0591ae6d21179d32e486b7a175b0f62bebeea866fcbb0ac5001fd7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 71b2c64ccc0591ae6d21179d32e486b7a175b0f62bebeea866fcbb0ac5001fd7
SHA3-384 hash: 2e9b4564bb663f3adfd7822f1a5531c961e89dc4b5b160667509fb2f8e4b1aec5c49f9575e3bf410b13092c3d848efe0
SHA1 hash: 17c512496c4fb54d46eb19ded51d2a7495d41751
MD5 hash: 16b90591eae642738815db7b0793e39e
humanhash: salami-carolina-berlin-chicken
File name:2021APT-28_74484453.js
Download: download sample
Signature TrickBot
File size:67'175 bytes
First seen:2021-07-29 05:13:25 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 1536:aTnL/zQ9Ry98guHVBqqg2bcruayUHmLKeZaMU7GwbWBPwVGWl9SZ8kV8Gp/5bzIx:afzQ9Ry98guHVBqqg2bcruzUHmLKeMMe
TLSH T1306378D82AD1E417338D2F17FE0A3AEAD1BA6C5796C47507D1587A5C24ED21BC6A0CF0
Reporter cocaman
Tags:js TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
442
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script.Downloader.SLoad
Status:
Malicious
First seen:
2021-07-29 05:14:15 UTC
File Type:
Text (JavaScript)
AV detection:
3 of 46 (6.52%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://smart-integrator.hr/pornhub.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

Java Script (JS) js 71b2c64ccc0591ae6d21179d32e486b7a175b0f62bebeea866fcbb0ac5001fd7

(this sample)

  
Delivery method
Other

Comments