🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1dd74d7301bf8d504449071142c81113bcd4d0c88fee46e7bacf550495a72bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: a1dd74d7301bf8d504449071142c81113bcd4d0c88fee46e7bacf550495a72bc
SHA3-384 hash: e18e5dffc6bde5d485a1b568629bd2fe584d30091cc0770288af3fbc2c3dc806a473c706f210d4569b148134238f63ae
SHA1 hash: 3e6a4041ed2be36ef85ccde8f170b75607887dfe
MD5 hash: 87936f0b8f079c7f722ab91029cc3f8a
humanhash: tango-arkansas-football-pip
File name:LisectAVT_2403002B_312.dll
Download: download sample
Signature TrickBot
File size:473'224 bytes
First seen:2024-07-25 01:13:34 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 87bed5a7cba00c7e1f4015f1bdae2183 (3'034 x Jadtre, 23 x IcedID, 23 x Blackmoon)
ssdeep 6144:7bVPXLakbTqht5o+nKivd8Z4sPYwp4KltOzlZRMCKy6fcWWHDecHAI3C+8hkBt:db4DmavdW4svpLtmRlKMHDuIyct
Threatray 2 similar samples on MalwareBazaar
TLSH T161A4AFFB668C0392E2036879EF18E2B7915367AD6F42C1C5F66AD9D72633052C51CB43
TrID 27.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
20.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.6% (.EXE) Win32 Executable (generic) (4504/4/1)
8.5% (.ICL) Windows Icons Library (generic) (2059/9)
8.3% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Anonymous
Tags:dll exe TrickBot


Avatar
Anonymous
this malware sample is very nasty!

Intelligence


File Origin
# of uploads :
1
# of downloads :
704
Origin country :
CN CN
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a file in the Windows subdirectories
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed sality trickbot zusy
Result
Threat name:
Trickbot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Infostealer.Tinba
Status:
Malicious
First seen:
2021-07-30 01:49:00 UTC
File Type:
PE (Sys)
AV detection:
28 of 38 (73.68%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:zev4 banker discovery trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Trickbot
Malware Config
C2 Extraction:
14.232.161.45:443
118.173.233.64:443
41.57.156.203:443
45.239.234.2:443
45.201.136.3:443
177.10.90.29:443
185.17.105.236:443
91.237.161.87:443
185.189.55.207:443
186.225.119.170:443
143.0.208.20:443
222.124.16.74:443
220.82.64.198:443
200.236.218.62:443
178.216.28.59:443
45.239.233.131:443
196.216.59.174:443
119.202.8.249:443
82.159.149.37:443
49.248.217.170:443
181.114.215.239:443
113.160.132.237:443
105.30.26.50:443
202.165.47.106:443
103.122.228.44:443
Unpacked files
SH256 hash:
03785fd170cd7ea05cf88112bdc802e0ad09e23465fb3f4cf12157b1cb545211
MD5 hash:
abe2bf165a001020d07f2200bc3f7e7a
SHA1 hash:
b935e0d78faa742ff0198ab411dfeb5eb41703b4
Detections:
win_trickbot_auto
SH256 hash:
8931a0dfe2dbc4840e39e37f4cf0c6b6fbf8969eaa03448a9a7d262402775447
MD5 hash:
cfe46def985e296269bb83b8bd636252
SHA1 hash:
13cad93db97c1ac9961f68ae3c063474c1342731
Detections:
win_trickbot_auto
SH256 hash:
a1dd74d7301bf8d504449071142c81113bcd4d0c88fee46e7bacf550495a72bc
MD5 hash:
87936f0b8f079c7f722ab91029cc3f8a
SHA1 hash:
3e6a4041ed2be36ef85ccde8f170b75607887dfe
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

DLL dll a1dd74d7301bf8d504449071142c81113bcd4d0c88fee46e7bacf550495a72bc

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN_BASE_APIUses Win Base APIKERNEL32.dll::LoadLibraryA

Comments