MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c2e5d2f0c63677e5391c6faea8eb8b0da15fcad2b626ea09ae2bafe0144bc2e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
TrickBot
Vendor detections: 7
| SHA256 hash: | c2e5d2f0c63677e5391c6faea8eb8b0da15fcad2b626ea09ae2bafe0144bc2e5 |
|---|---|
| SHA3-384 hash: | beb20077ab4f80772abd48557ec214d56aa00f11190560ffb6548b02f97aa2b482402866e6c98d30170a5e4ebfe24182 |
| SHA1 hash: | a499b437b9c9ade56e47749ee09effa96b88eaf7 |
| MD5 hash: | 9f565a7a08363ccf1a6403e4bc232909 |
| humanhash: | island-carolina-muppet-potato |
| File name: | triage_dropped_file |
| Download: | download sample |
| Signature | TrickBot |
| File size: | 413'311 bytes |
| First seen: | 2021-07-02 12:07:01 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 9c7729e7e6125436737710b1ba737d7e (4 x TrickBot) |
| ssdeep | 6144:54Gp1gZmFlZKmP4jrc9/5fS9XJqLSYmHiNKhV5X:JrgZm7ZKmP4jrGg9XKg6Kh |
| TLSH | D894E1226641C871D18B11399A7297755EAEBC129BB065CB2FE03EBF6F247C1CF35206 |
| Reporter | |
| Tags: | dll TrickBot |
Intelligence
File Origin
# of uploads :
1
# of downloads :
225
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Malware family:
TrickBot
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
72 / 100
Signature
Allocates memory in foreign processes
Delayed program exit found
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Behaviour
Behavior Graph:
Detection:
trickbot
Threat name:
Win32.Trojan.Trickpak
Status:
Malicious
First seen:
2021-07-02 12:07:12 UTC
AV detection:
16 of 46 (34.78%)
Threat level:
5/5
Result
Malware family:
trickbot
Score:
10/10
Tags:
family:trickbot botnet:zev1 banker trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
14.232.161.45:443
118.173.233.64:443
41.57.156.203:443
45.239.234.2:443
45.201.136.3:443
177.10.90.29:443
185.17.105.236:443
91.237.161.87:443
185.189.55.207:443
186.225.119.170:443
143.0.208.20:443
222.124.16.74:443
220.82.64.198:443
200.236.218.62:443
178.216.28.59:443
45.239.233.131:443
196.216.59.174:443
119.202.8.249:443
82.159.149.37:443
49.248.217.170:443
181.114.215.239:443
113.160.132.237:443
105.30.26.50:443
202.165.47.106:443
103.122.228.44:443
118.173.233.64:443
41.57.156.203:443
45.239.234.2:443
45.201.136.3:443
177.10.90.29:443
185.17.105.236:443
91.237.161.87:443
185.189.55.207:443
186.225.119.170:443
143.0.208.20:443
222.124.16.74:443
220.82.64.198:443
200.236.218.62:443
178.216.28.59:443
45.239.233.131:443
196.216.59.174:443
119.202.8.249:443
82.159.149.37:443
49.248.217.170:443
181.114.215.239:443
113.160.132.237:443
105.30.26.50:443
202.165.47.106:443
103.122.228.44:443
Unpacked files
SH256 hash:
c2e5d2f0c63677e5391c6faea8eb8b0da15fcad2b626ea09ae2bafe0144bc2e5
MD5 hash:
9f565a7a08363ccf1a6403e4bc232909
SHA1 hash:
a499b437b9c9ade56e47749ee09effa96b88eaf7
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.