🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 caf4706cf04d70dee7b0e6cbb70af2cf575f6b800b5aaae5dde7b1e3246d5f23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 12


Intelligence 12 IOCs YARA 1 File information Comments

SHA256 hash: caf4706cf04d70dee7b0e6cbb70af2cf575f6b800b5aaae5dde7b1e3246d5f23
SHA3-384 hash: baf350c94eac9b99a39b6e5c280655df1f64bb5b9250013129000d27bad66481c24f13c2cd9980f2588105988a075846
SHA1 hash: 11a54c8455421f50c44901f1381b770009cbec0e
MD5 hash: c0db57619980e33886e1468a3b195a88
humanhash: delaware-wyoming-yellow-high
File name:c0db57619980e33886e1468a3b195a88.exe
Download: download sample
Signature TrickBot
File size:516'096 bytes
First seen:2021-06-10 13:07:20 UTC
Last seen:2021-06-10 13:54:49 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f543eb9c59a7c5b3b080034d17f117f6 (1 x TrickBot)
ssdeep 12288:eLrRWXvVhVZUXiKZCXEg+hfrVdmZI87rF:fXvVhAXi70jhfRdZ8
Threatray 694 similar samples on MalwareBazaar
TLSH 89B4BE1635F581B3C3F3E1341BD1CB3AE1A8BADD5B53DA479FE0EB1E6A31490612A064
Reporter abuse_ch
Tags:exe nob3 TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
325
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
661662.docx
Verdict:
Malicious activity
Analysis date:
2021-06-09 20:28:01 UTC
Tags:
generated-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj.evad
Score:
88 / 100
Signature
Allocates memory in foreign processes
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Zenpak
Status:
Malicious
First seen:
2021-06-10 00:50:15 UTC
AV detection:
7 of 29 (24.14%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:nob3 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
196.43.106.38:443
186.97.172.178:443
37.228.70.134:443
144.48.139.206:443
190.110.179.139:443
172.105.15.152:443
177.67.137.111:443
27.72.107.215:443
186.66.15.10:443
189.206.78.155:443
202.131.227.229:443
185.9.187.10:443
196.41.57.46:443
212.200.25.118:443
197.254.14.238:443
45.229.71.211:443
181.167.217.53:443
181.129.116.58:443
185.189.55.207:443
172.104.241.29:443
14.241.244.60:443
144.48.138.213:443
202.138.242.7:443
202.166.196.111:443
36.94.100.202:443
187.19.167.233:443
181.129.242.202:443
36.94.27.124:443
43.245.216.116:443
186.225.63.18:443
41.77.134.250:443
Unpacked files
SH256 hash:
8d51973c19ee79015d05f98381e7bf5d28816e577e5aab5a165d1c7c3ec6c7da
MD5 hash:
6bdd6bddd187548bfdb810f474ad8133
SHA1 hash:
bd21e039d6ee2f4964f8933400921662c58e2df9
Detections:
win_trickbot_a4 win_trickbot_g6 win_trickbot_auto
SH256 hash:
f157f2a631cc25952c36cffa940892f374d88a7500e3a1b3f1356e8ffe2358b5
MD5 hash:
59b25b65cb39cfe6229b80efb698e94b
SHA1 hash:
2f4efa165e6c9936dbc416e088ca2b269fe57851
SH256 hash:
65f03bab287a87a37d8cf9bbdc0f095a6624de83876c0cb41323e37cb0c97703
MD5 hash:
c0721f6ed040f6661d73c6f1e1e056c1
SHA1 hash:
37a670562a8df1bc02a2af0dc3073e8792668877
Detections:
win_trickbot_auto
SH256 hash:
caf4706cf04d70dee7b0e6cbb70af2cf575f6b800b5aaae5dde7b1e3246d5f23
MD5 hash:
c0db57619980e33886e1468a3b195a88
SHA1 hash:
11a54c8455421f50c44901f1381b770009cbec0e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Cobalt_functions
Author:@j0sm1
Description:Detect functions coded with ROR edi,D; Detect CobaltStrike used by differents groups APT

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

Executable exe caf4706cf04d70dee7b0e6cbb70af2cf575f6b800b5aaae5dde7b1e3246d5f23

(this sample)

  
Delivery method
Distributed via web download

Comments