MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3674599d872cf73497b4b5171828be5e9cd7da892b1eb54ddfb4593e94587d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: c3674599d872cf73497b4b5171828be5e9cd7da892b1eb54ddfb4593e94587d4
SHA3-384 hash: b09d9ab120a371e18c182f798a498922203d6040176bd5b3b5ffd8026207f6d28738f7a97b46adeed1a7c96010b1d9c9
SHA1 hash: d0b89092ee86a154a6c4252bd8f3cedb90773a63
MD5 hash: 24b3e1f23f5382ff30cd43ef8fa68ce6
humanhash: jupiter-quebec-july-avocado
File name:24b3e1f23f5382ff30cd43ef8fa68ce6.dll
Download: download sample
Signature TrickBot
File size:690'688 bytes
First seen:2021-03-16 19:08:02 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash cae73998be5b008dd1c2d777a562de39 (3 x TrickBot)
ssdeep 12288:RFq5gJqjDe8jUCYPnXjX/5n85pFb856xaBm6yOD0kVUU2:/0+jXBnApFo6xaM2YkVUd
Threatray 2 similar samples on MalwareBazaar
TLSH 0FE4AE117AE0D071C57E36705416E77852ADE8B06F6D87CB6FC42A3F6E312C29A3835A
Reporter abuse_ch
Tags:dll mon139 TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
296
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 369604 Sample: 9v8fA4PbIy.dll Startdate: 16/03/2021 Architecture: WINDOWS Score: 56 27 Multi AV Scanner detection for submitted file 2->27 29 Yara detected Trickbot 2->29 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 20 8->12         started        14 regsvr32.exe 8->14         started        process5 16 iexplore.exe 1 75 10->16         started        process6 18 iexplore.exe 147 16->18         started        dnsIp7 21 edge.gycpi.b.yahoodns.net 87.248.118.22, 443, 49750, 49751 YAHOO-DEBDE United Kingdom 18->21 23 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49745, 49746 FASTLYUS United States 18->23 25 11 other IPs or domains 18->25
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2021-03-15 16:59:36 UTC
AV detection:
12 of 28 (42.86%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:mon139 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
103.225.138.94:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
Unpacked files
SH256 hash:
3dee294eda88c4134bf45c9ad73a0ed353f9ac5ecd136191fb1b940778929c27
MD5 hash:
603cbc148e4240f94cd14525448d1d6f
SHA1 hash:
6d4c1a5954be499a697794d2c4da8e8058cdb711
SH256 hash:
4e3ffb96db2a8d51ba0af8b3dd767b1ad62fd53f72f467ceed5536208a620000
MD5 hash:
ad48234998d37d4ca115df0389221134
SHA1 hash:
a627d44c5354245782441beae771d7e3173ecc82
Detections:
win_trickbot_a4 win_trickbot_auto
SH256 hash:
67d76ec2d2c06d0ceb117bdf4ef3d2b23dd595b66154281632917631a8fd70b1
MD5 hash:
89491177c80f31520222624f3534da17
SHA1 hash:
cde8aa7a1ab52d031b45eb53ec336b0084ecb629
SH256 hash:
c3674599d872cf73497b4b5171828be5e9cd7da892b1eb54ddfb4593e94587d4
MD5 hash:
24b3e1f23f5382ff30cd43ef8fa68ce6
SHA1 hash:
d0b89092ee86a154a6c4252bd8f3cedb90773a63
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll c3674599d872cf73497b4b5171828be5e9cd7da892b1eb54ddfb4593e94587d4

(this sample)

Comments