🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 952c85cf4f3ccc3db9216ce021dc8cc299818d09f16d323b7a7e12fb91300cb8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments 1

SHA256 hash: 952c85cf4f3ccc3db9216ce021dc8cc299818d09f16d323b7a7e12fb91300cb8
SHA3-384 hash: 623a7c5b40d4b5bf8d7382161498df44799a00d771f0062b6200b4c34726d81a5a8123d65eb068f3cc81af6cde3cda4a
SHA1 hash: d5c0f93a69ef5c563e3a87344d02e105acc5480b
MD5 hash: 785d3deeac14f25235a4ceb46c7d55a8
humanhash: kilo-oregon-arkansas-wisconsin
File name:785d3deeac14f25235a4ceb46c7d55a8
Download: download sample
Signature TrickBot
File size:862'208 bytes
First seen:2021-07-15 15:04:42 UTC
Last seen:2021-07-15 15:42:17 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash a9b6c26936cbed29ffdd5c3c54f9fb9a (2 x TrickBot)
ssdeep 24576:BVTACesroRxoEo8nuSsgIMG/UU6hjl7f2:zAC7QxoEoSuSsgO/alu
Threatray 3'380 similar samples on MalwareBazaar
TLSH T19405CF12FEC19836E1AA1175CD36CBFC12A87E70FEE082276B847B5E6E36441B934355
Reporter zbetcheckin
Tags:32 dll exe TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
231
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj.evad
Score:
96 / 100
Signature
Allocates memory in foreign processes
Delayed program exit found
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Hijacks the control flow in another process
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 449423 Sample: PRIaTJGJO2 Startdate: 15/07/2021 Architecture: WINDOWS Score: 96 85 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->85 87 Found malware configuration 2->87 89 Multi AV Scanner detection for submitted file 2->89 91 Yara detected Trickbot 2->91 9 loaddll32.exe 1 2->9         started        12 rundll32.exe 2->12         started        14 regsvr32.exe 2->14         started        16 rundll32.exe 2->16         started        process3 signatures4 97 Writes to foreign memory regions 9->97 99 Allocates memory in foreign processes 9->99 18 regsvr32.exe 9->18         started        21 cmd.exe 1 9->21         started        23 rundll32.exe 9->23         started        25 3 other processes 9->25 process5 dnsIp6 93 Writes to foreign memory regions 18->93 95 Allocates memory in foreign processes 18->95 28 wermgr.exe 18->28         started        32 cmd.exe 18->32         started        34 rundll32.exe 21->34         started        36 wermgr.exe 23->36         started        38 cmd.exe 23->38         started        59 190.61.43.241, 443, 49780 UFINETPANAMASAPA Colombia 25->59 61 45.36.99.184, 443, 49771, 49776 TWC-11426-CAROLINASUS United States 25->61 63 9 other IPs or domains 25->63 40 iexplore.exe 146 25->40         started        42 cmd.exe 25->42         started        signatures7 process8 dnsIp9 65 185.81.51.44, 443, 49775, 49778 VIA-SMSLV Latvia 28->65 67 148.235.154.164, 443, 49785 UninetSAdeCVMX Mexico 28->67 73 15 other IPs or domains 28->73 101 Tries to detect virtualization through RDTSC time measurements 28->101 103 Found evasive API chain (trying to detect sleep duration tampering with parallel thread) 28->103 44 cmd.exe 28->44         started        105 Hijacks the control flow in another process 34->105 107 Writes to foreign memory regions 34->107 109 Allocates memory in foreign processes 34->109 111 Delayed program exit found 34->111 46 wermgr.exe 34->46         started        49 cmd.exe 34->49         started        69 24.162.214.166, 443, 49760, 49767 TWC-11427-TEXASUS United States 36->69 71 204.138.26.60, 443, 49755, 49757 NTT-COMMUNICATIONS-2914US United States 36->71 75 8 other IPs or domains 36->75 51 cmd.exe 36->51         started        77 13 other IPs or domains 40->77 53 conhost.exe 42->53         started        signatures10 process11 dnsIp12 55 conhost.exe 44->55         started        79 68.69.26.182, 443 KOS-1193CA Canada 46->79 81 201.55.206.238, 443 JANCHARLESRUECKERT-EPPBR Brazil 46->81 83 13 other IPs or domains 46->83 57 conhost.exe 51->57         started        process13
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2021-07-15 00:57:20 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:sat2 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
38.110.103.124:443
185.56.76.28:443
204.138.26.60:443
60.51.47.65:443
74.85.157.139:443
68.69.26.182:443
38.110.103.136:443
38.110.103.18:443
138.34.28.219:443
185.56.76.94:443
217.115.240.248:443
24.162.214.166:443
80.15.2.105:443
154.58.23.192:443
38.110.100.104:443
45.36.99.184:443
185.56.76.108:443
185.56.76.72:443
138.34.28.35:443
97.83.40.67:443
38.110.103.113:443
38.110.100.142:443
184.74.99.214:443
103.105.254.17:443
62.99.76.213:443
82.159.149.52:443
38.110.100.33:443
38.110.100.242:443
185.13.79.3:443
Unpacked files
SH256 hash:
88011430d2ed651b2b163face1d369a69f1826c06c38833263e5fd7f31f39db8
MD5 hash:
8d0e678c462f9e4fb1175f7f96a2aa87
SHA1 hash:
fcaf983df7a8c462f9312e7d337b03f50656beee
SH256 hash:
799ebebd0331b9d5cf25fb1de1bd9a46a595cb7507e1f3a5afcf58b21ad0908f
MD5 hash:
3c0477d7ce41f9edda0a4a795229b0af
SHA1 hash:
b6e476581b65b9ed8fc06d283752e4559e6ab23f
SH256 hash:
d956f331bd6e5e1b96f5f4c13f1005da2924aba74ddd6fe6d7c7e08ded52a3d2
MD5 hash:
cc777952c20e083f1817144cd5a1561d
SHA1 hash:
1abf71b9b28935e36471c3c0d31e753723d0f7d3
SH256 hash:
86ab779c12d77a59d53a0ffc812455c81a835750396450a54aea208cd60fc671
MD5 hash:
0030eac1b98495c75729db5b8189eebb
SHA1 hash:
03aa3b989682986379d4bd0c9a2a674aaa1543a8
SH256 hash:
952c85cf4f3ccc3db9216ce021dc8cc299818d09f16d323b7a7e12fb91300cb8
MD5 hash:
785d3deeac14f25235a4ceb46c7d55a8
SHA1 hash:
d5c0f93a69ef5c563e3a87344d02e105acc5480b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFuture
Author:ditekSHen
Description:Detect executables with stomped PE compilation timestamp that is greater than local current time

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll 952c85cf4f3ccc3db9216ce021dc8cc299818d09f16d323b7a7e12fb91300cb8

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-07-15 15:04:43 UTC

url : hxxp://185.209.160.61/2.php