🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e45cc54b2d0faaf9870ed2d7b4f7febd2cb4bc119e6989c23f29411085bd889d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments 1

SHA256 hash: e45cc54b2d0faaf9870ed2d7b4f7febd2cb4bc119e6989c23f29411085bd889d
SHA3-384 hash: 4310ed00b645a00504f23cf4ed4471189cae95d5c5908fee4bd0cf263eaed7654ee965207db088852bf15dce03de4ad7
SHA1 hash: 18d3fdd405989e288fb827a85cd72173bd40c858
MD5 hash: 2c9eb27739df36e159da9d34e438baf3
humanhash: five-mirror-michigan-jig
File name:mon92.dll
Download: download sample
Signature TrickBot
File size:1'085'516 bytes
First seen:2021-05-07 05:15:19 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash d32b4b1906fa2ea31b12c4d6e80d5b9d (3 x TrickBot)
ssdeep 12288:ihm3t/45Iz5tby4y9MijCW9C7hCrplztZbbEPb3Z7wxjt:u+/4YnhUlpXbU7Mt
Threatray 253 similar samples on MalwareBazaar
TLSH 17352826B170C835D3B94230CDD5AAAC72E5AC718F6429D376407B8E7A76AD1C639333
Reporter starsSk87264403
Tags:TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
269
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj
Score:
64 / 100
Signature
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 406725 Sample: mon92.dll Startdate: 07/05/2021 Architecture: WINDOWS Score: 64 40 Found malware configuration 2->40 42 Multi AV Scanner detection for submitted file 2->42 44 Yara detected Trickbot 2->44 7 loaddll32.exe 1 2->7         started        process3 process4 9 iexplore.exe 2 71 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 25 7->13         started        15 8 other processes 7->15 process5 17 iexplore.exe 154 9->17         started        20 WerFault.exe 11->20         started        22 wermgr.exe 13->22         started        24 WerFault.exe 23 9 15->24         started        26 rundll32.exe 15->26         started        28 WerFault.exe 15->28         started        30 2 other processes 15->30 dnsIp6 32 tls13.taboola.map.fastly.net 151.101.1.44, 443, 49732, 49733 FASTLYUS United States 17->32 34 geolocation.onetrust.com 104.20.184.68, 443, 49718, 49719 CLOUDFLARENETUS United States 17->34 38 8 other IPs or domains 17->38 36 192.168.2.1 unknown unknown 20->36
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2021-03-01 17:54:27 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
e45cc54b2d0faaf9870ed2d7b4f7febd2cb4bc119e6989c23f29411085bd889d
MD5 hash:
2c9eb27739df36e159da9d34e438baf3
SHA1 hash:
18d3fdd405989e288fb827a85cd72173bd40c858
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll e45cc54b2d0faaf9870ed2d7b4f7febd2cb4bc119e6989c23f29411085bd889d

(this sample)

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-07 06:14:25 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [F0002.002] Collection::Polling
1) [C0031] Cryptography Micro-objective::Decrypt Data
2) [C0027.009] Cryptography Micro-objective::RC4::Encrypt Data
3) [C0027] Cryptography Micro-objective::Encrypt Data
4) [C0021.004] Cryptography Micro-objective::RC4 PRGA::Generate Pseudo-random Sequence
6) [C0045] File System Micro-objective::Copy File
7) [C0049] File System Micro-objective::Get File Attributes
8) [C0051] File System Micro-objective::Read File
9) [C0050] File System Micro-objective::Set File Attributes
10) [C0052] File System Micro-objective::Writes File
11) [C0034.001] Operating System Micro-objective::Set Variable::Environment Variable
12) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
13) [C0036.002] Operating System Micro-objective::Delete Registry Key::Registry
14) [C0036.007] Operating System Micro-objective::Delete Registry Value::Registry
15) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
16) [C0036.005] Operating System Micro-objective::Query Registry Key::Registry
17) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
18) [C0036.001] Operating System Micro-objective::Set Registry Key::Registry
19) [C0040] Process Micro-objective::Allocate Thread Local Storage
20) [C0038] Process Micro-objective::Create Thread
21) [C0054] Process Micro-objective::Resume Thread
22) [C0041] Process Micro-objective::Set Thread Local Storage Value
23) [C0055] Process Micro-objective::Suspend Thread
24) [C0018] Process Micro-objective::Terminate Process