🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7cbc5e5dc182c8d99809cd64d36734abeb6bfac15e6efc2ebcc2c57254bf172. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 14


Intelligence 14 IOCs YARA 3 File information Comments

SHA256 hash: b7cbc5e5dc182c8d99809cd64d36734abeb6bfac15e6efc2ebcc2c57254bf172
SHA3-384 hash: 40acf4c4f672dbc849d4159fd71d4207eacd324b359a76c2d12afcac8b3e2be9bd01af57e34423a9f8e310096cd2a3ed
SHA1 hash: 516c7a538e93f7cf4bff29196511f94e5fbb5a40
MD5 hash: 8402ab33eafb84178069f8f490ca604d
humanhash: echo-bakerloo-sierra-pluto
File name:sefff993.bin
Download: download sample
Signature TrickBot
File size:377'097 bytes
First seen:2022-07-08 09:22:51 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f3ca748f76db44ff1430515217457e6d (1 x TrickBot)
ssdeep 6144:jo5N5OazOZaTDWlVnrchrahdOxveC2wo80/agxb0zLz4qM:jmSuOcHmnYhrDMTrban4qM
TLSH T13F84A7FC56C61611B0ECCDB7C7129F6AF655BF535328B29A284C82BD702283F0259A77
TrID 46.4% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
29.5% (.EXE) Win64 Executable (generic) (10523/12/4)
12.6% (.EXE) Win32 Executable (generic) (4505/5/1)
5.6% (.EXE) Generic Win/DOS Executable (2002/3)
5.6% (.EXE) DOS Executable Generic (2000/1)
Reporter KdssSupport
Tags:exe TrickBot


Avatar
KdssSupport
Uploaded with API

Intelligence


File Origin
# of uploads :
1
# of downloads :
892
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
sefff993.exe
Verdict:
Malicious activity
Analysis date:
2022-07-08 08:24:33 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changing a file
Launching cmd.exe command interpreter
Creating a process with a hidden window
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Launching a process
Sending an HTTP GET request
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Blocking the Windows Defender launch
Unauthorized injection to a system process
Enabling autorun by creating a file
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
SystemUptime
EvasionGetTickCount
EvasionQueryPerformanceCounter
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
Trickbot
Detection:
malicious
Classification:
bank.troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Disable Windows Defender notifications (registry)
Disables Windows Defender (via service or powershell)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for domain / URL
Writes to foreign memory regions
Yara detected PersistenceViaHiddenTask
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 659572 Sample: sefff993.bin Startdate: 08/07/2022 Architecture: WINDOWS Score: 100 79 Multi AV Scanner detection for domain / URL 2->79 81 Antivirus / Scanner detection for submitted sample 2->81 83 Yara detected Trickbot 2->83 85 2 other signatures 2->85 8 sefff993.exe 1 20 2->8         started        12 tefff993.exe 2->12         started        14 tefff993.exe 2->14         started        process3 file4 63 C:\Users\user\AppData\...\tefff993.exe, PE32 8->63 dropped 65 C:\Users\...\tefff993.exe:Zone.Identifier, ASCII 8->65 dropped 89 Disable Windows Defender notifications (registry) 8->89 91 Disables Windows Defender (via service or powershell) 8->91 16 tefff993.exe 8 8->16         started        19 cmd.exe 1 8->19         started        21 cmd.exe 1 8->21         started        23 cmd.exe 1 8->23         started        93 Writes to foreign memory regions 12->93 95 Allocates memory in foreign processes 12->95 97 Injects a PE file into a foreign processes 12->97 25 cmd.exe 12->25         started        27 cmd.exe 12->27         started        31 2 other processes 12->31 29 cmd.exe 14->29         started        34 3 other processes 14->34 signatures5 process6 dnsIp7 69 Antivirus detection for dropped file 16->69 71 Machine Learning detection for dropped file 16->71 73 Writes to foreign memory regions 16->73 77 2 other signatures 16->77 36 4 other processes 16->36 75 Disables Windows Defender (via service or powershell) 19->75 39 2 other processes 19->39 41 2 other processes 21->41 43 2 other processes 23->43 45 2 other processes 25->45 47 2 other processes 27->47 49 2 other processes 29->49 67 190.14.157.148, 449 TELCOCOMAR Argentina 31->67 51 2 other processes 31->51 53 4 other processes 34->53 signatures8 process9 signatures10 87 Disables Windows Defender (via service or powershell) 36->87 55 powershell.exe 24 36->55         started        57 conhost.exe 36->57         started        59 conhost.exe 36->59         started        61 3 other processes 36->61 process11
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2022-07-08 09:23:23 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
21 of 25 (84.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
trickbot
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot banker evasion trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Launches sc.exe
Drops file in System32 directory
Loads dropped DLL
Executes dropped EXE
Stops running service(s)
Trickbot
Trickbot x86 loader
Unpacked files
SH256 hash:
e00e95897b84894c09782a9fb8e495bfd872b601deb1c178b07d08b83f86165f
MD5 hash:
edd19ad71e777295edc2b4d92dc60d75
SHA1 hash:
86fc4c54503053382875d50674456e5a2044aaea
Detections:
win_trickbot_a4 win_trickbot_auto
SH256 hash:
41970da1d6e5d984f2d65277e8819bcf15d453b77b1044db028f842e1ab3798b
MD5 hash:
419f5e416a3150d75acb94bd48b0cde8
SHA1 hash:
84f0d880d162beed05f19f0d7fb1fcf3bde16393
Detections:
win_trickbot_auto
SH256 hash:
b7cbc5e5dc182c8d99809cd64d36734abeb6bfac15e6efc2ebcc2c57254bf172
MD5 hash:
8402ab33eafb84178069f8f490ca604d
SHA1 hash:
516c7a538e93f7cf4bff29196511f94e5fbb5a40
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Intezer_Vaccine_Trickbot
Author:Intezer Labs
Description:Automatic YARA vaccination rule created based on the file's genes
Reference:https://analyze.intezer.com
Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB
Rule name:win_trickbot_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.trickbot.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

Executable exe b7cbc5e5dc182c8d99809cd64d36734abeb6bfac15e6efc2ebcc2c57254bf172

(this sample)

  
Delivery method
Distributed via web download

Comments