🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0b5a3a3542d34a360e41033b01ecc6df78639ffd47a6044f97e711fd33c8f5e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 2


Intelligence 2 IOCs YARA 1 File information Comments

SHA256 hash: a0b5a3a3542d34a360e41033b01ecc6df78639ffd47a6044f97e711fd33c8f5e
SHA3-384 hash: aa3591ee38b52cc00d0a0e0194028298d1708ec85e3b311e3a0f311757177263ac1411060c2d07ec67c8303ded683fc2
SHA1 hash: b325dfddd8b2399df5240b7f825785d0af33b8a6
MD5 hash: ac8d28f43c14fb74bcc492654ab90874
humanhash: xray-oscar-eleven-sweet
File name:details_5750.js
Download: download sample
Signature TrickBot
File size:626'634 bytes
First seen:2021-07-26 19:19:43 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:4er6y3vBmx5hKdYb6IpXtSPUKXAugotE8E6/HZbK4WvNOpIFxUqM4INCaMP49qjY:YaPwxUOcC+fp
TLSH T1B9D4AF90EB8011132BCB6757FD0226E2E93D80129280325BD59D775C2B975D9C3BAFBE
Reporter notajungman
Tags:js TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://netvalleykenya.com/crm.php
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:unknown_dropper
Author:#evilcel3ri
Description:Detects an unknown dropper

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

Java Script (JS) js a0b5a3a3542d34a360e41033b01ecc6df78639ffd47a6044f97e711fd33c8f5e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments