MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae3ac27e8303519cf04a053a424a0939ecc3905a9a62f33bae3a29f069251b1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ae3ac27e8303519cf04a053a424a0939ecc3905a9a62f33bae3a29f069251b1f
SHA3-384 hash: 8a2ee2f14bde054a7491bff7ecf586d30efc41a3b3332d0d1f5e293ab0a7dc03ba9084012358aedd95a52d1097f9e5aa
SHA1 hash: e0af4cca8631b950802f3f322fbb936ca287c314
MD5 hash: e973766c13539766302b0dafb7a8acc9
humanhash: ink-rugby-stream-angel
File name:aeiouy.dll
Download: download sample
Signature TrickBot
File size:24'576 bytes
First seen:2020-11-30 22:47:56 UTC
Last seen:2020-12-01 13:54:08 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7802a2afdb884b4d1a51c221c6ef5fcd (3 x BuerLoader, 2 x TrickBot)
ssdeep 384:cMd1wVcTN/p7Ff3Yunx02sdYda+12w515JaixQNctxyxQcMmZMIMyDseU:jdS6TNxJXmdYd52w5HTd7yxRZvMssP
Threatray 1 similar samples on MalwareBazaar
TLSH A6B26D93749BC476C3202B751F86741292E86E2071B7E2F77A6C1CC87CB4A9BD729352
Reporter James_inthe_box
Tags:dll TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
109
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-30 22:47:49 UTC
File Type:
PE (Exe)
AV detection:
19 of 28 (67.86%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
trickbot
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
ae3ac27e8303519cf04a053a424a0939ecc3905a9a62f33bae3a29f069251b1f
MD5 hash:
e973766c13539766302b0dafb7a8acc9
SHA1 hash:
e0af4cca8631b950802f3f322fbb936ca287c314
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments