🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4ad69ba5f948a165b7443439a9dfd9d84d71b4c729bbe3909b493dbe84cad7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: a4ad69ba5f948a165b7443439a9dfd9d84d71b4c729bbe3909b493dbe84cad7b
SHA3-384 hash: d441e7513c993f1d636753246c6cdfbf06632c52f5504d0f2394a469fbdb089be2b1452b189025501f23e069dc9669e2
SHA1 hash: 4b4c683ca22aaa919ef58a5af417073b37ea94f9
MD5 hash: d56e4b539b3316f09313fabb4b7b4c4a
humanhash: mississippi-fix-jig-may
File name:建信人寿保险股份有限公司天津分公司第二季度五月份考勤异常登记表202206131013.exe
Download: download sample
Signature TrickBot
File size:134'144 bytes
First seen:2022-06-13 15:59:06 UTC
Last seen:2022-06-13 16:49:48 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c55fb8b4b38cd18b83d9759e886fff0f (1 x TrickBot)
ssdeep 3072:SpDRuLpVAWmLAo3DGdIyzWWMOXThodeTZwyH1X:QMze8o3D8y6eiWy
Threatray 2'634 similar samples on MalwareBazaar
TLSH T179D35C5B73A534F9E5B6853589908905D372BC710BA18FAF03A062969F372D0AD3EF30
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
File icon (PE):PE icon
dhash icon 74ecc4e2e4e4e0d4 (2 x TrickBot)
Reporter obfusor
Tags:exe TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
517
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
建信人寿保险股份有限公司天津分公司第二季度五月份考勤异常登记表202206131013.exe
Verdict:
No threats detected
Analysis date:
2022-06-13 20:47:04 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
EvasionQueryPerformanceCounter
CheckCmdLine
Gathering data
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Zenpak
Status:
Malicious
First seen:
2022-06-13 07:52:31 UTC
File Type:
PE+ (Exe)
Extracted files:
3
AV detection:
15 of 26 (57.69%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
a4ad69ba5f948a165b7443439a9dfd9d84d71b4c729bbe3909b493dbe84cad7b
MD5 hash:
d56e4b539b3316f09313fabb4b7b4c4a
SHA1 hash:
4b4c683ca22aaa919ef58a5af417073b37ea94f9
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments