🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89d87f486616ff7319976c10f14e995ec939aa698d64bd48bac68f392c4da302. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 11


Intelligence 11 IOCs YARA 1 File information Comments

SHA256 hash: 89d87f486616ff7319976c10f14e995ec939aa698d64bd48bac68f392c4da302
SHA3-384 hash: 786e637fafb4458909960cbf69c215399ef305a4c03fecca3fea57fa08751314316de98123099a7eeac85ec07e4c2088
SHA1 hash: b410499500f161bbd70607f550f3d9244c103b59
MD5 hash: c01a94ff81534257ca8bf10993e7794f
humanhash: nevada-mike-dakota-artist
File name:borderCurr.jpg
Download: download sample
Signature TrickBot
File size:626'776 bytes
First seen:2021-07-16 20:25:11 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 9f325b9ad7eb6a885ed588ae8ed1dc00 (2 x TrickBot)
ssdeep 12288:1hO5t+bI1p1CcMNYzvEXR76y1XjNcWJa29rvFCs:1hrbI1pklYLEXfjCca29rvf
Threatray 3'428 similar samples on MalwareBazaar
TLSH T1B3D4AE1372D0CC75DAAB02355922C76852FAFD309EF5C247BF807B6D5E325438A2A366
Reporter malware_traffic
Tags:dll Shathak TA551 TrickBot zev1

Intelligence


File Origin
# of uploads :
1
# of downloads :
235
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Trickbot
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Hijacks the control flow in another process
Initial sample is a PE file and has a suspicious name
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Svchost Process
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 450116 Sample: borderCurr.jpg Startdate: 16/07/2021 Architecture: WINDOWS Score: 100 87 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->87 89 Found malware configuration 2->89 91 Yara detected Trickbot 2->91 93 4 other signatures 2->93 9 loaddll32.exe 1 2->9         started        12 rundll32.exe 2->12         started        14 regsvr32.exe 2->14         started        16 rundll32.exe 2->16         started        process3 signatures4 101 Writes to foreign memory regions 9->101 103 Allocates memory in foreign processes 9->103 18 regsvr32.exe 9->18         started        21 cmd.exe 1 9->21         started        23 rundll32.exe 9->23         started        25 2 other processes 9->25 process5 dnsIp6 95 Writes to foreign memory regions 18->95 97 Allocates memory in foreign processes 18->97 28 wermgr.exe 18->28         started        32 rundll32.exe 21->32         started        34 wermgr.exe 23->34         started        67 118.173.233.64, 443, 49781 TOT-NETTOTPublicCompanyLimitedTH Thailand 25->67 69 185.189.55.207, 443, 49790 TELLCOM-ASTR Turkey 25->69 71 10 other IPs or domains 25->71 99 Hijacks the control flow in another process 25->99 36 iexplore.exe 145 25->36         started        38 svchost.exe 10 25->38         started        40 svchost.exe 25->40         started        signatures7 process8 dnsIp9 73 14.232.161.45, 443 VNPT-AS-VNVNPTCorpVN Viet Nam 28->73 75 45.239.234.2, 443, 49776 SPEEDNETFRUTALNETFIBRAEWIRELESSBR Brazil 28->75 81 8 other IPs or domains 28->81 109 Hijacks the control flow in another process 28->109 111 Writes to foreign memory regions 28->111 113 Tries to detect virtualization through RDTSC time measurements 28->113 115 Found evasive API chain (trying to detect sleep duration tampering with parallel thread) 28->115 42 svchost.exe 28->42         started        46 svchost.exe 28->46         started        117 Allocates memory in foreign processes 32->117 48 wermgr.exe 32->48         started        77 200.236.218.62, 443, 49794, 49811 TelecomSouthAmericaSABR Brazil 34->77 83 7 other IPs or domains 34->83 51 svchost.exe 34->51         started        85 12 other IPs or domains 36->85 79 12.23.113.92, 443 ATT-INTERNET4US United States 38->79 signatures10 process11 dnsIp12 55 C:\Users\user\AppData\Local\...\Web Data.bak, SQLite 42->55 dropped 57 C:\Users\user\AppData\...\Login Data.bak, SQLite 42->57 dropped 59 C:\Users\user\AppData\Local\...\History.bak, SQLite 42->59 dropped 105 Tries to harvest and steal browser information (history, passwords, etc) 42->105 61 185.17.105.236, 443, 49777 ASN-WARIANInternetServiceProviderEU Italy 48->61 63 wtfismyip.com 95.217.228.176, 49810, 80 HETZNER-ASDE Germany 48->63 65 5 other IPs or domains 48->65 107 Writes to foreign memory regions 48->107 53 svchost.exe 48->53         started        file13 signatures14 process15
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-07-16 20:26:04 UTC
AV detection:
13 of 28 (46.43%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:zev1 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
14.232.161.45:443
118.173.233.64:443
41.57.156.203:443
45.239.234.2:443
45.201.136.3:443
177.10.90.29:443
185.17.105.236:443
91.237.161.87:443
185.189.55.207:443
186.225.119.170:443
143.0.208.20:443
222.124.16.74:443
220.82.64.198:443
200.236.218.62:443
178.216.28.59:443
45.239.233.131:443
196.216.59.174:443
119.202.8.249:443
82.159.149.37:443
49.248.217.170:443
181.114.215.239:443
113.160.132.237:443
105.30.26.50:443
202.165.47.106:443
103.122.228.44:443
Unpacked files
SH256 hash:
f7f17be21bfba69a126a6f385f2ecdffb09361dd55fd5681f52c606567ca5418
MD5 hash:
f28c1bedbf0165d349d94dd9a0dbf0c7
SHA1 hash:
905f1d1563f01b0b58673a377c6ece4ae34f2528
Detections:
win_trickbot_auto
SH256 hash:
ab1c0428e7d5b87ad343b4e7823bd56c02619ed7253281b9d96e16e695aa553a
MD5 hash:
e2064c9a0a2c5de4ec4f59b61f70dca1
SHA1 hash:
59319a9d36836e4a38abd333215fa2dfa0d6bbf1
SH256 hash:
880a47a27e12e51adceaf722a85cb43baab6f4092ed874be6f72931a22ef8444
MD5 hash:
763ef41825e3ed92be445e8d322dcb56
SHA1 hash:
47dac77ab419c73b081d1e35f157ed0c7bea612b
SH256 hash:
18235de7e0a1c094556b623df7a3f417b8ffdaac52882581891c218e64975751
MD5 hash:
5596dd47c8ff1df27117f571ae737a2a
SHA1 hash:
4254b6109f05cebe502cf253ff7b6acacdf6fd32
SH256 hash:
89d87f486616ff7319976c10f14e995ec939aa698d64bd48bac68f392c4da302
MD5 hash:
c01a94ff81534257ca8bf10993e7794f
SHA1 hash:
b410499500f161bbd70607f550f3d9244c103b59
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFuture
Author:ditekSHen
Description:Detect executables with stomped PE compilation timestamp that is greater than local current time

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments