MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f3c8bc00960cf4d8c190ada51ebfd80c4997cee9de8cb8fbd075e61391d9c734. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f3c8bc00960cf4d8c190ada51ebfd80c4997cee9de8cb8fbd075e61391d9c734
SHA3-384 hash: 911ae6db7a3c35f0dbaa301915ad6c4c0bb410f4cf6a492d7539a9ab6741fc301200f7137103c4b4c442b7d0f5b403f5
SHA1 hash: 8ea0600045016026ccee38da81068ac1659ea50a
MD5 hash: ab6c685e3340cd5f5d94049814002880
humanhash: delaware-connecticut-uranus-venus
File name:f3c8bc00960cf4d8c190ada51ebfd80c4997cee9de8cb8fbd075e61391d9c734
Download: download sample
Signature TrickBot
File size:381'028 bytes
First seen:2020-06-05 10:02:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 069b2cf668627f6f2aa71975aeab1b31 (1 x TrickBot)
ssdeep 6144:CKhVeSawYl7YCjs81NxlFHnIGY3wvsxZV9cAqe3Wtcm4ce7DByDi8f4Ku:Ph0SxussNxlFHn5YtV1TGGDByXfa
Threatray 5'064 similar samples on MalwareBazaar
TLSH 02840122EE670991F76A5A3049F96BB94A2B6B143B258CCB87C0FD4D54777C0AF2310D
Reporter raashidbhatt
Tags:TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2020-06-05 11:51:12 UTC
AV detection:
29 of 31 (93.55%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:ono20 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Modifies data under HKEY_USERS
Loads dropped DLL
Executes dropped EXE
Trickbot
Trickbot x86 loader
Malware Config
C2 Extraction:
51.68.247.62:443
37.228.117.146:443
91.132.139.170:443
37.44.212.216:443
31.184.253.37:443
51.254.69.244:443
194.5.250.82:443
5.230.22.40:443
185.222.202.222:443
46.30.41.229:443
203.23.128.168:443
190.154.203.218:449
189.80.134.122:449
200.116.199.10:449
181.113.20.186:449
187.58.56.26:449
146.196.122.167:449
177.103.240.149:449
181.199.102.179:449
200.21.51.38:449
181.49.61.237:449
190.152.4.210:449
138.59.233.5:449
36.89.85.103:449
45.161.33.88:449
186.42.185.10:449
170.233.120.53:449
187.110.100.122:449
200.153.15.178:449
186.42.98.254:449
181.129.93.226:449
186.42.226.46:449
190.13.160.19:449
186.183.199.114:449
170.84.78.117:449
190.152.4.98:449
181.196.61.110:449
138.185.25.228:449
200.35.56.81:449
186.42.186.202:449
185.70.182.162:449
91.207.185.73:449
181.129.49.98:449
181.115.168.69:449
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments