🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc0e27ef89ef3f3399f818185aa8800226468ca5f47fc2e912a353e617070f4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: dc0e27ef89ef3f3399f818185aa8800226468ca5f47fc2e912a353e617070f4b
SHA3-384 hash: 5529333857dc423e6fb7be925eb48c9d31073cf97759bba9ad42abceeb9126c5d63b1f33b7c2b6f07d0fa30467e337e2
SHA1 hash: b8337607d11b15d8380f9637892ef587d8e2bbdd
MD5 hash: 37c04f26e0b5602ec6e60c310a74e707
humanhash: kentucky-bakerloo-utah-friend
File name:37c04f26e0b5602ec6e60c310a74e707.dll
Download: download sample
Signature TrickBot
File size:476'160 bytes
First seen:2021-09-11 10:58:58 UTC
Last seen:2021-09-11 12:11:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 92ebe261b8d7879345d45855cc60d775 (1 x TrickBot)
ssdeep 3072:m4wJsJO8IUDPxWowANxTEDju83zzB2ooZutHkjKr86UWG:dw2DZWEQ3NnB2CkFt
Threatray 2 similar samples on MalwareBazaar
TLSH T180A47E16B2E444BFE8268235CCA35906E77278211724CB6F0764437A5F7B3A19E3EF61
Reporter Anonymous
Tags:dll exe TrickBot X64

Intelligence


File Origin
# of uploads :
2
# of downloads :
196
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
37c04f26e0b5602ec6e60c310a74e707.dll
Verdict:
No threats detected
Analysis date:
2021-09-11 11:01:35 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Delayed writing of the file
Launching a process
Creating a process with a hidden window
Creating a window
Launching the default Windows debugger (dwwin.exe)
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Sigma detected: Regsvr32 Command Line Without DLL
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 481569 Sample: crIZ8f4zob.dll Startdate: 11/09/2021 Architecture: WINDOWS Score: 56 57 Multi AV Scanner detection for submitted file 2->57 59 Sigma detected: Regsvr32 Command Line Without DLL 2->59 8 loaddll64.exe 2 2->8         started        11 Calculator.exe 2->11         started        process3 signatures4 61 Tries to detect virtualization through RDTSC time measurements 8->61 13 regsvr32.exe 1 8->13         started        17 cmd.exe 1 8->17         started        19 rundll32.exe 1 8->19         started        21 5 other processes 8->21 process5 dnsIp6 55 192.168.2.1 unknown unknown 13->55 65 Tries to detect virtualization through RDTSC time measurements 13->65 23 calc.exe 12 13->23         started        25 WerFault.exe 13->25         started        27 WerFault.exe 13->27         started        29 rundll32.exe 1 17->29         started        39 3 other processes 19->39 32 iexplore.exe 146 21->32         started        35 calc.exe 12 21->35         started        37 calc.exe 21->37         started        41 6 other processes 21->41 signatures7 process8 dnsIp9 63 Tries to detect virtualization through RDTSC time measurements 29->63 43 calc.exe 29->43         started        45 WerFault.exe 29->45         started        47 WerFault.exe 29->47         started        49 edge.gycpi.b.yahoodns.net 87.248.118.22, 443, 49848, 49849 YAHOO-DEBDE United Kingdom 32->49 51 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49845, 49846 FASTLYUS United States 32->51 53 11 other IPs or domains 32->53 signatures10 process11
Threat name:
Win64.Trojan.Razy
Status:
Malicious
First seen:
2021-06-09 11:14:36 UTC
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
trickbot
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
dc0e27ef89ef3f3399f818185aa8800226468ca5f47fc2e912a353e617070f4b
MD5 hash:
37c04f26e0b5602ec6e60c310a74e707
SHA1 hash:
b8337607d11b15d8380f9637892ef587d8e2bbdd
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments