🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9fd496babcf95d302a07fe68f7659b7d5c47b6316d3723b2ee81ba92ab5d944d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 9fd496babcf95d302a07fe68f7659b7d5c47b6316d3723b2ee81ba92ab5d944d
SHA3-384 hash: 18b584ee4e39a2e94d811e9a1713229068b459b8404ed4ad2d85581d76817899360c63a6bfb9766a9be750c1a41f5218
SHA1 hash: 38b7fe09ef8c1e8e9e39796f147d74715e9dac8d
MD5 hash: cfc5b1a3b7cc9db2332d90c8101b1a4b
humanhash: freddie-south-grey-item
File name:cfc5b1a3b7cc9db2332d90c8101b1a4b.dll
Download: download sample
Signature TrickBot
File size:440'320 bytes
First seen:2021-11-22 13:28:13 UTC
Last seen:2021-11-22 15:49:25 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 12288:IVwHWB3VyqZ8WMSOUUaBaVcVHd6mcJiyQsumQcF1NlfmIUQ32nnjGe:2wHYNUGLBaVcV96mc4yruEfrb3CjGe
Threatray 12 similar samples on MalwareBazaar
TLSH T14994AFFB538C5AD9E147BCBECA10F1E7D1A2AE730F12D184FA116A9399354A6C904F43
Reporter abuse_ch
Tags:dll TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
803
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
DNS request
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj.evad
Score:
88 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 526605 Sample: Q8mCCAFHMT.dll Startdate: 22/11/2021 Architecture: WINDOWS Score: 88 45 Found malware configuration 2->45 47 Antivirus detection for URL or domain 2->47 49 Multi AV Scanner detection for submitted file 2->49 51 Yara detected Trickbot 2->51 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        15 rundll32.exe 8->15         started        17 4 other processes 8->17 signatures5 19 rundll32.exe 10->19         started        57 Writes to foreign memory regions 12->57 59 Allocates memory in foreign processes 12->59 22 wermgr.exe 12->22         started        25 cmd.exe 12->25         started        27 wermgr.exe 15->27         started        29 cmd.exe 15->29         started        process6 dnsIp7 53 Writes to foreign memory regions 19->53 55 Allocates memory in foreign processes 19->55 31 wermgr.exe 19->31         started        35 cmd.exe 19->35         started        37 185.56.175.122, 443, 49718, 49784 VIRTUAOPERATOR-ASPL Poland 22->37 signatures8 process9 dnsIp10 39 46.99.175.149, 443, 49717, 49783 IPKO-ASAL Albania 31->39 41 Tries to detect virtualization through RDTSC time measurements 31->41 43 Found evasive API chain (trying to detect sleep duration tampering with parallel thread) 31->43 signatures11
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2021-11-22 13:29:10 UTC
File Type:
PE (Sys)
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:soh1 banker suricata trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Trickbot
suricata: ET MALWARE Win32/TrickBot CnC Initial Checkin M2
Malware Config
C2 Extraction:
65.152.201.203:443
185.56.175.122:443
46.99.175.217:443
179.189.229.254:443
46.99.175.149:443
181.129.167.82:443
216.166.148.187:443
46.99.188.223:443
128.201.76.252:443
62.99.79.77:443
60.51.47.65:443
24.162.214.166:443
45.36.99.184:443
97.83.40.67:443
184.74.99.214:443
103.105.254.17:443
62.99.76.213:443
82.159.149.52:443
Unpacked files
SH256 hash:
be1690963a36b21df98b26dd903270fb7d35b84364dac797a176f1dfcdbc0784
MD5 hash:
8ae36fc397fe782381a4b81382ae3c4c
SHA1 hash:
8836f9486bf36a9412979c1ab630192e813b0578
SH256 hash:
9fd496babcf95d302a07fe68f7659b7d5c47b6316d3723b2ee81ba92ab5d944d
MD5 hash:
cfc5b1a3b7cc9db2332d90c8101b1a4b
SHA1 hash:
38b7fe09ef8c1e8e9e39796f147d74715e9dac8d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll 9fd496babcf95d302a07fe68f7659b7d5c47b6316d3723b2ee81ba92ab5d944d

(this sample)

  
Delivery method
Distributed via web download

Comments