🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 758cb2d6a4c0ea0e21b0db00bd427f41d3d679883701e7865809e20a4ca89f7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 758cb2d6a4c0ea0e21b0db00bd427f41d3d679883701e7865809e20a4ca89f7a
SHA3-384 hash: 4116b852798b1d2a1f9cf0bab41f7b6c7232780f4e00c823ec24104144db483bc525329c006bc5dcf78877b8f68de417
SHA1 hash: b6cda924b9641b40305ce100acbbf342dd479c5d
MD5 hash: d9fa69ac4fcc720b34a7fed3ed9d1586
humanhash: butter-minnesota-oklahoma-red
File name:1.dot
Download: download sample
Signature TrickBot
File size:810'116 bytes
First seen:2021-12-10 10:49:28 UTC
Last seen:2021-12-10 12:36:19 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash c24b5af71e321f46094351d9a2bf63c3 (1 x TrickBot)
ssdeep 12288:InhdroYY4VgbjWuEs3OLX2nhdroYY4VgbjWuEs3OLXx:m7YwYhQXw7YwYhQXx
TLSH T1EE05F120B2A0C431C45B2935927ADA715A3F3D32EAF58547BBA837385F722C09B7D365
File icon (PE):PE icon
dhash icon c0b1a0b2b4b434f4 (7 x TrickBot)
Reporter proxylife
Tags:dll rob142 TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
899
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Creating a file in the system32 subdirectories
Sending a custom TCP request
Creating a file
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 537739 Sample: 1.dll Startdate: 10/12/2021 Architecture: WINDOWS Score: 56 24 Multi AV Scanner detection for submitted file 2->24 26 Machine Learning detection for sample 2->26 28 Sigma detected: Suspicious Call by Ordinal 2->28 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 1 8->12         started        14 rundll32.exe 8->14         started        process5 16 rundll32.exe 10->16         started        18 WerFault.exe 23 9 12->18         started        20 WerFault.exe 9 14->20         started        process6 22 WerFault.exe 2 9 16->22         started       
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2021-12-10 10:50:12 UTC
File Type:
PE (Dll)
Extracted files:
7
AV detection:
21 of 27 (77.78%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:rob142 banker trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
181.129.85.98:443
189.112.119.205:443
189.51.118.78:443
186.121.214.106:443
49.176.188.184:443
61.69.102.170:443
213.32.252.221:443
89.46.216.2:443
103.36.79.3:443
103.108.97.51:443
95.140.217.242:443
41.175.22.226:443
190.109.169.161:443
186.159.12.18:443
190.109.171.17:443
181.196.148.202:443
186.47.75.58:443
186.42.212.30:443
190.214.21.14:443
187.108.32.133:443
201.184.226.74:443
186.159.5.177:443
Unpacked files
SH256 hash:
758cb2d6a4c0ea0e21b0db00bd427f41d3d679883701e7865809e20a4ca89f7a
MD5 hash:
d9fa69ac4fcc720b34a7fed3ed9d1586
SHA1 hash:
b6cda924b9641b40305ce100acbbf342dd479c5d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments