MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee22d1b889f577512fc9a45da2ce24a1ddcafdf1fd412f8dd42aa3b112d1fa91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ee22d1b889f577512fc9a45da2ce24a1ddcafdf1fd412f8dd42aa3b112d1fa91
SHA3-384 hash: 084c79f1ef753dfed42d666291b4ee252da33ed21927ceeb1a285ef93d5d9b6f0e0dcdedf1c1d11df2e3a18922a5108e
SHA1 hash: 848270d1c11a4b0d8543833df323082e998c1171
MD5 hash: 26d27317025124ac585c1a463e2986e4
humanhash: zulu-winner-angel-fillet
File name:ee22d1b889f577512fc9a45da2ce24a1ddcafdf1fd412f8dd42aa3b112d1fa91
Download: download sample
Signature TrickBot
File size:443'392 bytes
First seen:2020-03-23 16:19:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 79a558cff49bd5306ac49553c8e95ea3 (1 x TrickBot)
ssdeep 6144:tbn0BY4x8KRX4qUrpmhKySRsF/EP5jta58cdf2PkMd7NxSZ7i6Kjoh2kkkkkkkkn:tb0W4x8sJKFiKPdM+2De7TXU
Threatray 10 similar samples on MalwareBazaar
TLSH 7294BF4276E0DE34D02655B05D24C733C839EDE87B01AA9F6347A6A95DEB3C069433AF
Reporter Marco_Ramilli
Tags:exe TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

Executable exe ee22d1b889f577512fc9a45da2ce24a1ddcafdf1fd412f8dd42aa3b112d1fa91

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.DLL::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.DLL::LoadLibraryA
KERNEL32.DLL::GetStartupInfoA
KERNEL32.DLL::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.DLL::SetConsoleCtrlHandler
WIN_BASE_IO_APICan Create FilesKERNEL32.DLL::CreateFileA
WIN_CRYPT_APIUses Windows Crypt APIADVAPI32.DLL::CryptAcquireContextA
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.DLL::CreateServiceA
ADVAPI32.DLL::OpenSCManagerA
ADVAPI32.DLL::OpenServiceA
ADVAPI32.DLL::RegisterServiceCtrlHandlerA
ADVAPI32.DLL::StartServiceCtrlDispatcherA

Comments