🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee
SHA3-384 hash: 2f0ed9fedf30a3277b2274d48782cb0661992401bdb668b57f72503d485751cd671f109ff1c834d0bc815184300c0898
SHA1 hash: ca3565ba0b524ee1600d266335e151a408deac4c
MD5 hash: a80c7aa74e2813864b9796521380d193
humanhash: pluto-triple-lake-mars
File name:147.dll
Download: download sample
Signature TrickBot
File size:757'761 bytes
First seen:2021-03-19 18:19:38 UTC
Last seen:2021-03-19 19:47:52 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 27af48f5c723652212203558f954e963 (3 x TrickBot)
ssdeep 12288:/GkcUcJTpz8UmB12Zdf9Mc1FCd+sRvD5tj9yt:jcjpoXf2Z1WaOvRbXjg
Threatray 6 similar samples on MalwareBazaar
TLSH 4EF4BF03FA90D1F5D27D647468114B2156E9ECA0EEF5C6C35B85FE8D8E3A2C2622D393
Reporter p5yb34m
Tags:dll mon147 TrickBot


Avatar
p5yb34m
Source:
https://ozpinarco[.]com/wp-content/themes/archi-child/images/prettyPhoto/147.dll

Intelligence


File Origin
# of uploads :
2
# of downloads :
321
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Sending a UDP request
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj
Score:
60 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 372220 Sample: 147.dll Startdate: 19/03/2021 Architecture: WINDOWS Score: 60 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Trickbot 2->34 36 Machine Learning detection for sample 2->36 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 20 8->12         started        14 regsvr32.exe 8->14         started        process5 16 iexplore.exe 2 84 10->16         started        19 cmd.exe 12->19         started        dnsIp6 24 192.168.2.1 unknown unknown 16->24 21 iexplore.exe 5 155 16->21         started        process7 dnsIp8 26 edge.gycpi.b.yahoodns.net 87.248.118.23, 443, 49724, 49725 YAHOO-DEBDE United Kingdom 21->26 28 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49718, 49719 FASTLYUS United States 21->28 30 10 other IPs or domains 21->30
Threat name:
Win32.Trojan.Emotet
Status:
Malicious
First seen:
2021-03-18 02:10:13 UTC
AV detection:
23 of 47 (48.94%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:mon147 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
103.225.138.94:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
Unpacked files
SH256 hash:
9b12748bf534e0b0aadc41839761817be2feef7e2b7aa8c07ac67082ba790597
MD5 hash:
141f39556015663b149c6987f8120fbf
SHA1 hash:
17664ed5c73b9d2a13fc1bf136b1de5f105bb844
SH256 hash:
744a4b030a040c0b49b891a35b48adee89773edde43fb67254292fc99519171c
MD5 hash:
879475b3292db2586e862a7f88e26162
SHA1 hash:
225f5173fa0ae238c9d36afe7e2da54c9bf7bdea
SH256 hash:
16d3c32e05b47eaf46037c475031133ed4a86410a89a3203bfa4222b00cda366
MD5 hash:
2f182b18031009233406a40ef390be8c
SHA1 hash:
fc6630ff9543ff08d90b6e17eac0f29d998a4256
Detections:
win_trickbot_a4 win_trickbot_auto
SH256 hash:
aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee
MD5 hash:
a80c7aa74e2813864b9796521380d193
SHA1 hash:
ca3565ba0b524ee1600d266335e151a408deac4c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll aed2b8d91256d038c0452ec74b6757f667955ae2d1488a2c5ab0b97c5fa8b2ee

(this sample)

Comments