MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 9
| SHA256 hash: | aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee |
|---|---|
| SHA3-384 hash: | 2f0ed9fedf30a3277b2274d48782cb0661992401bdb668b57f72503d485751cd671f109ff1c834d0bc815184300c0898 |
| SHA1 hash: | ca3565ba0b524ee1600d266335e151a408deac4c |
| MD5 hash: | a80c7aa74e2813864b9796521380d193 |
| humanhash: | pluto-triple-lake-mars |
| File name: | 147.dll |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 757'761 bytes |
| First seen: | 2021-03-19 18:19:38 UTC |
| Last seen: | 2021-03-19 19:47:52 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 27af48f5c723652212203558f954e963 (3 x TrickBot) |
| ssdeep | 12288:/GkcUcJTpz8UmB12Zdf9Mc1FCd+sRvD5tj9yt:jcjpoXf2Z1WaOvRbXjg |
| Threatray | 6 similar samples on MalwareBazaar |
| TLSH | 4EF4BF03FA90D1F5D27D647468114B2156E9ECA0EEF5C6C35B85FE8D8E3A2C2622D393 |
| Reporter | |
| Tags: | dll mon147 TrickBot |
Intelligence
File Origin
# of uploads :
2
# of downloads :
321
Origin country :
n/a
Vendor Threat Intelligence
Detection:
TrickBot
Result
Verdict:
Clean
Maliciousness:
Behaviour
Sending a custom TCP request
Sending a UDP request
Verdict:
Malicious
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj
Score:
60 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Trickbot
Behaviour
Behavior Graph:
Detection:
trickbot
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2021-03-18 02:10:13 UTC
AV detection:
23 of 47 (48.94%)
Threat level:
5/5
Verdict:
malicious
Similar samples:
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:mon147 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
103.225.138.94:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
Unpacked files
SH256 hash:
9b12748bf534e0b0aadc41839761817be2feef7e2b7aa8c07ac67082ba790597
MD5 hash:
141f39556015663b149c6987f8120fbf
SHA1 hash:
17664ed5c73b9d2a13fc1bf136b1de5f105bb844
SH256 hash:
744a4b030a040c0b49b891a35b48adee89773edde43fb67254292fc99519171c
MD5 hash:
879475b3292db2586e862a7f88e26162
SHA1 hash:
225f5173fa0ae238c9d36afe7e2da54c9bf7bdea
SH256 hash:
16d3c32e05b47eaf46037c475031133ed4a86410a89a3203bfa4222b00cda366
MD5 hash:
2f182b18031009233406a40ef390be8c
SHA1 hash:
fc6630ff9543ff08d90b6e17eac0f29d998a4256
Detections:
win_trickbot_a4
win_trickbot_auto
SH256 hash:
aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee
MD5 hash:
a80c7aa74e2813864b9796521380d193
SHA1 hash:
ca3565ba0b524ee1600d266335e151a408deac4c
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Emotet
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.