MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b43ae26d4c95a64acb84a54f87c38d86c9133606ee6eb31d65e7c1b4a146409. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7b43ae26d4c95a64acb84a54f87c38d86c9133606ee6eb31d65e7c1b4a146409
SHA3-384 hash: 9fffacd752688c6db9328eb46a142233276064622c5999539430a99c48540b7755d261d0e6e36be562bd57a69ab6c050
SHA1 hash: a87f1ee384199d931a9b03d378b31a3815184c93
MD5 hash: 1d2df806533d0feb19607e9b597a8214
humanhash: moon-jupiter-yankee-tennis
File name:jse_fixed.exe
Download: download sample
Signature TrickBot
File size:774'144 bytes
First seen:2020-04-30 07:37:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9ff661430ac75da92544a71d35f8af4b (1 x TrickBot)
ssdeep 12288:T2RhiXCojG6IvwswYmhgeHL8ZEu+Kdg9HMoadPmMRseQVQCzL9CcTPHR5ut+n:aTiXVswYmTH+rEsnNSeQieLgQH
Threatray 4'954 similar samples on MalwareBazaar
TLSH F3F4BE067A70C1B6C2C292304FEFBF95E6F99E914D311D83B7D84B5C293AC91C72A619
Reporter jarumlus
Tags:TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::SetFileSecurityA
COM_BASE_APICan Download & Execute componentsole32.dll::CLSIDFromProgID
ole32.dll::CoFreeUnusedLibraries
ole32.dll::CreateStreamOnHGlobal
MULTIMEDIA_APICan Play MultimediaGDI32.dll::StretchDIBits
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::SetFileSecurityW
SHELL_APIManipulates System ShellSHELL32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetVolumeInformationA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetDiskFreeSpaceA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::SetStdHandle
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileA
KERNEL32.dll::CreateFileA
ole32.dll::CreateFileMoniker
KERNEL32.dll::DeleteFileA
ADVAPI32.dll::GetFileSecurityA
KERNEL32.dll::MoveFileA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyA
ADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegDeleteKeyA
ADVAPI32.dll::RegOpenKeyA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryValueA
ADVAPI32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuA
USER32.dll::FindWindowA
USER32.dll::OpenClipboard
USER32.dll::PeekMessageA
USER32.dll::CreateWindowExA

Comments