MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1b96c57c9d7ca04322e828c77aeed1b1ff0e02a27e69d028b7745dc1de1bec4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a1b96c57c9d7ca04322e828c77aeed1b1ff0e02a27e69d028b7745dc1de1bec4
SHA3-384 hash: 893bca7035763a39f8190caafc7e45a2f2b0fc4ae1b7724a8889c2b0357c32d8478c4895852c447e42f939ffa19b806c
SHA1 hash: dab971f06b81b6eee613b6d22da15887c852b898
MD5 hash: 9e53885b2e12639a7f5f295eda2846f4
humanhash: whiskey-eleven-lithium-twenty
File name:9e53885b2e12639a7f5f295eda2846f4.exe
Download: download sample
File size:241'152 bytes
First seen:2020-07-30 07:15:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9059fa0902c45563d36cfd269e1b61bf
ssdeep 3072:C+3lo+ZbrqUDdBkEQO0c1VgzAxgbrzyV9sbbQf0UvnM4wC8N3JmI0abDvohJSKI:Za+JrqYtQO0c1Vg8Crtm0eQC8vYabjh
Threatray 1'202 similar samples on MalwareBazaar
TLSH 77341229E2D99491C0729B7600E68E15A07AF63257B207EF0528C94D6A733C8FFF761D
Reporter abuse_ch
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Transferring files using the Background Intelligent Transfer Service (BITS)
Connection attempt
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw
Score:
52 / 100
Signature
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Keylogger Generic
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.TrickBot
Status:
Malicious
First seen:
2020-07-29 00:46:00 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments