🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e407df6434b2dd7f904dba54ffb68c7dde7d9f7deb259b73ecd3cad050008613. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments 1

SHA256 hash: e407df6434b2dd7f904dba54ffb68c7dde7d9f7deb259b73ecd3cad050008613
SHA3-384 hash: 972dfcb5cd793d34053fa77194afd807b7329ee6c923c487117dd789be7c078f50b971adc8506b7ea0c10dff4e582f48
SHA1 hash: b1ca7f3c47ffb591eb92eafa7370c586493f2416
MD5 hash: 454a4bbbbc3a8ed7715d659d17d30d9d
humanhash: london-minnesota-island-timing
File name:8B924320.dll
Download: download sample
Signature TrickBot
File size:585'728 bytes
First seen:2021-05-18 13:45:54 UTC
Last seen:2021-05-18 14:55:17 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash a83818d75741576c469ee0021da3d4b1 (1 x TrickBot)
ssdeep 12288:S14v+jDkWFLORcCr5HJaJ+a2l401agoNRBc:S1boWFOr5HY+Tj1pKRBc
Threatray 121 similar samples on MalwareBazaar
TLSH 39C4D0127AD4817AD9FF12701E762B35A7FDA9209F61C5CBE790C90C6D725C2DA3A302
Reporter ffforward
Tags:dll Rob82 TrickBot

Intelligence


File Origin
# of uploads :
2
# of downloads :
300
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
Allocates memory in foreign processes
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Found malware configuration
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 416462 Sample: 8B924320.dll Startdate: 18/05/2021 Architecture: WINDOWS Score: 72 40 Found malware configuration 2->40 42 Yara detected Trickbot 2->42 9 loaddll32.exe 1 2->9         started        process3 process4 11 rundll32.exe 9->11         started        14 rundll32.exe 9->14         started        16 cmd.exe 1 9->16         started        18 6 other processes 9->18 signatures5 48 Writes to foreign memory regions 11->48 50 Allocates memory in foreign processes 11->50 20 wermgr.exe 11->20         started        23 rundll32.exe 16->23         started        25 WerFault.exe 22 9 18->25         started        27 WerFault.exe 9 18->27         started        29 WerFault.exe 3 18->29         started        31 WerFault.exe 18->31         started        process6 signatures7 44 Tries to detect virtualization through RDTSC time measurements 20->44 46 Found evasive API chain (trying to detect sleep duration tampering with parallel thread) 20->46 33 WerFault.exe 3 9 23->33         started        process8 dnsIp9 38 192.168.2.1 unknown unknown 33->38 36 wermgr.exe 33->36         started        process10
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-18 14:00:35 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [B0012.001] Anti-Static Analysis::Argument Obfuscation
1) [F0002.002] Collection::Polling
2) [C0027.009] Cryptography Micro-objective::RC4::Encrypt Data
3) [C0021.004] Cryptography Micro-objective::RC4 PRGA::Generate Pseudo-random Sequence
4) [C0049] File System Micro-objective::Get File Attributes
5) [C0051] File System Micro-objective::Read File
6) [C0050] File System Micro-objective::Set File Attributes
7) [C0052] File System Micro-objective::Writes File
8) [C0034.001] Operating System Micro-objective::Set Variable::Environment Variable
9) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
10) [C0036.002] Operating System Micro-objective::Delete Registry Key::Registry
11) [C0036.007] Operating System Micro-objective::Delete Registry Value::Registry
12) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
13) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
14) [C0036.001] Operating System Micro-objective::Set Registry Key::Registry
15) [C0040] Process Micro-objective::Allocate Thread Local Storage
16) [C0038] Process Micro-objective::Create Thread
17) [C0054] Process Micro-objective::Resume Thread
18) [C0041] Process Micro-objective::Set Thread Local Storage Value
19) [C0055] Process Micro-objective::Suspend Thread
20) [C0018] Process Micro-objective::Terminate Process