MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8a022ddcef8459ab71cdc33f3474779df507a25ca4d179279be78424c69c813. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: d8a022ddcef8459ab71cdc33f3474779df507a25ca4d179279be78424c69c813
SHA3-384 hash: b989436ceb832066d20931cfa895e5e8b2ba1c5ece9e336456f851470ffee9efe69ea6e3d90dfa381530d2a36b05fe0b
SHA1 hash: 2993c6b4ed199302a7d98dba08a7c07e1506d159
MD5 hash: 9abd93765b72a724c25d6c9a2b6c0d1e
humanhash: jupiter-solar-spring-alaska
File name:9abd93765b72a724c25d6c9a2b6c0d1e.exe
Download: download sample
Signature TrickBot
File size:729'151 bytes
First seen:2021-11-14 07:23:04 UTC
Last seen:2021-11-14 09:10:00 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b1583b0de68b5707a7d41293f45591df (9 x TrickBot)
ssdeep 6144:9/Z8DzzV0Xl2D3cowVtWGC0m9LYLr5XY1HUoG/D4gHpb9K8LHnhEoXYzo:QzzV0Xl2TGCLOR2fFgJb9FhTXYzo
Threatray 3'953 similar samples on MalwareBazaar
TLSH T11BF4E0A236E48076E5B601320EB67B3A96FBEC644F79FBC31390974D5E310D1493936A
File icon (PE):PE icon
dhash icon 71b119dcce576333 (3'570 x Heodo, 203 x TrickBot, 19 x Gh0stRAT)
Reporter abuse_ch
Tags:exe TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
295
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a process
Sending a UDP request
Connection attempt
Forced shutdown of a system process
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware keylogger overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Trickbot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2021-11-14 07:24:07 UTC
AV detection:
24 of 28 (85.71%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:lib177 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
36.91.117.231:443
36.89.228.201:443
103.75.32.173:443
45.115.172.105:443
36.95.23.89:443
103.123.86.104:443
202.65.119.162:443
202.9.121.143:443
139.255.65.170:443
110.172.137.20:443
103.146.232.154:443
36.91.88.164:443
103.47.170.131:443
122.117.90.133:443
103.9.188.78:443
210.2.149.202:443
118.91.190.42:443
117.222.61.115:443
117.222.57.92:443
136.228.128.21:443
103.47.170.130:443
36.91.186.235:443
103.194.88.4:443
116.206.153.212:443
58.97.72.83:443
139.255.6.2:443
Unpacked files
SH256 hash:
509744afff9d24808c672bc71e3e4ddbf016d93af41f0a5f6353d078ca5bcba1
MD5 hash:
b5819de7122318bf019875dd3d245100
SHA1 hash:
8c5940ce0950613907701398bd5e2b8b831b8fbf
SH256 hash:
f75700e634855110de074c667d20a95af891e9a171bd3362e054cc266a942c3e
MD5 hash:
997b80d646be03976bd67441fdc50087
SHA1 hash:
6d3abbfb7d2d84c43e05c3a46c7e16691f03b490
Detections:
win_trickbot_auto
SH256 hash:
0952c2c1af64f62f654911b43c2f773963079f0653fc6848b116db96cf8e6149
MD5 hash:
8040db7f45d6e1fe0054a61dd2f3eb50
SHA1 hash:
c54e990539c2067237e8d835e43cd05eecb1f57c
SH256 hash:
d8a022ddcef8459ab71cdc33f3474779df507a25ca4d179279be78424c69c813
MD5 hash:
9abd93765b72a724c25d6c9a2b6c0d1e
SHA1 hash:
2993c6b4ed199302a7d98dba08a7c07e1506d159
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

Executable exe d8a022ddcef8459ab71cdc33f3474779df507a25ca4d179279be78424c69c813

(this sample)

  
Delivery method
Distributed via web download

Comments