🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f604acdbac81768352ca2105a5efb82fb84544e8000a69b3d0a9ac5d557db8b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments 1

SHA256 hash: f604acdbac81768352ca2105a5efb82fb84544e8000a69b3d0a9ac5d557db8b8
SHA3-384 hash: 738f623d46cbb4809a4129ac5dbb7262dc413d0c55b9ed7779bc0db819888180c822d968a8e181e0870a5b0d83f0cbf3
SHA1 hash: 00bd8e2267700a0c7c12b92500c1cf1a90f39e6a
MD5 hash: 090492c95603c772ea19a92b5f1fb8f3
humanhash: high-idaho-maine-nuts
File name:mon117(1).dll
Download: download sample
Signature TrickBot
File size:429'568 bytes
First seen:2021-05-07 05:15:27 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 88be6a3f02e620b370d6f4da1dd6d20a (2 x TrickBot)
ssdeep 12288:qS5JKcaGxx7BwKjPpemSxLB7JrEm1oB8zU1fz5O:qSH/xxomIr+8gt5
Threatray 36 similar samples on MalwareBazaar
TLSH 1E94E11077C0C137E6AF1D3989FBA7259B2D75060B26CBC76784CD664F962E29E3034A
Reporter starsSk87264403
Tags:TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
280
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Sending a UDP request
Result
Threat name:
TrickBot
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected Trickbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 406723 Sample: mon117(1).dll Startdate: 07/05/2021 Architecture: WINDOWS Score: 68 30 Found malware configuration 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Trickbot 2->34 36 Machine Learning detection for sample 2->36 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 20 8->12         started        14 rundll32.exe 8 8->14         started        16 2 other processes 8->16 process5 18 rundll32.exe 8 10->18         started        20 cmd.exe 12->20         started        22 cmd.exe 14->22         started        24 WerFault.exe 23 9 16->24         started        26 WerFault.exe 2 9 16->26         started        process6 28 cmd.exe 18->28         started       
Threat name:
Win32.Trojan.TrickBotCrypt
Status:
Malicious
First seen:
2021-03-12 23:18:00 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:mon117 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Templ.dll packer
Trickbot
Malware Config
C2 Extraction:
103.225.138.94:449
122.2.28.70:449
123.200.26.246:449
131.255.106.152:449
142.112.79.223:449
154.126.176.30:449
180.92.238.186:449
187.20.217.129:449
201.20.118.122:449
202.91.41.138:449
95.210.118.90:449
Unpacked files
SH256 hash:
cdf8fa2b677a110901b459d7a006394d0503a7f66f00ee81f7df21d1a11c5761
MD5 hash:
d87481130651b71a029d32af13be7a64
SHA1 hash:
cb603868fe3aa213a7df34c15dfdd02aff44b101
SH256 hash:
77a45f16547fbf7c9211a3f08ea90229b5390815c63492cc422f94bca0ad8d93
MD5 hash:
82ff4f1748d9eae4f729aaced3ec91b1
SHA1 hash:
7c55477322152b1a3aa74ac67c2b2cbd2b25aa7a
Detections:
win_trickbot_a4 win_trickbot_auto
SH256 hash:
aaea0ecc636fb8d6014c484dcd1cbb6eb89e73360b714ed53746e948fa79c03c
MD5 hash:
7c82698b04d24f323347788a96281e35
SHA1 hash:
3f1ff4120a2dac50e19e59721c4270c1164fc3b4
SH256 hash:
f604acdbac81768352ca2105a5efb82fb84544e8000a69b3d0a9ac5d557db8b8
MD5 hash:
090492c95603c772ea19a92b5f1fb8f3
SHA1 hash:
00bd8e2267700a0c7c12b92500c1cf1a90f39e6a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll f604acdbac81768352ca2105a5efb82fb84544e8000a69b3d0a9ac5d557db8b8

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-07 06:11:03 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [C0002.014] Communication Micro-objective::Read Header::HTTP Communication
1) [C0027.009] Cryptography Micro-objective::RC4::Encrypt Data
2) [C0021.004] Cryptography Micro-objective::RC4 PRGA::Generate Pseudo-random Sequence
3) [C0019] Data Micro-objective::Check String
4) [C0026.001] Data Micro-objective::Base64::Encode Data
5) [C0052] File System Micro-objective::Writes File
6) [C0007] Memory Micro-objective::Allocate Memory
7) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
8) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
9) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
10) [C0040] Process Micro-objective::Allocate Thread Local Storage
11) [C0054] Process Micro-objective::Resume Thread
12) [C0041] Process Micro-objective::Set Thread Local Storage Value
13) [C0018] Process Micro-objective::Terminate Process