🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ccd4dace71bb5a5dba4251ca0f4780095ddd8bebcb0cbeaed66cb3799bca2fe6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ccd4dace71bb5a5dba4251ca0f4780095ddd8bebcb0cbeaed66cb3799bca2fe6
SHA3-384 hash: ed3329ecdc2726cf728bd56f277dc9592d3826dfa79ec2a48b8fb3ae70fa6e52ea665dc1d1419a643da3459e04744f1d
SHA1 hash: cfc2112e4f6304e1d4bcbcf0d3d005bf447d163e
MD5 hash: 7b039064a7976d3de3737b6a2a651483
humanhash: september-ohio-earth-uranus
File name:b6ec985f433a33d1c9c38ad7ab288bc2be516075391b67a64cc36f3f668fb1c3.bin.sample.gz
Download: download sample
Signature TrickBot
File size:457'811 bytes
First seen:2021-11-11 07:06:38 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:SRFUWzl9hsOwqvSPj0n+OjXBcUPdB0aQEY:SzUWz+ySPQ+OtxP0wY
TLSH T129A4D0207380C037E56320B98AEAC7B55B7EB9715761A4CB3BC60A7D5F355D2AA3430E
Reporter KodaES
Tags:gz TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
352
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm greyware hacktool packed trickbot
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2021-11-11 07:07:03 UTC
AV detection:
22 of 44 (50.00%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:rob128 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
65.152.201.203:443
185.56.175.122:443
46.99.175.217:443
179.189.229.254:443
46.99.175.149:443
181.129.167.82:443
216.166.148.187:443
46.99.188.223:443
128.201.76.252:443
62.99.79.77:443
60.51.47.65:443
24.162.214.166:443
45.36.99.184:443
97.83.40.67:443
184.74.99.214:443
103.105.254.17:443
62.99.76.213:443
82.159.149.52:443
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments