🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f894a027474fa36723db3644d7dc1715dbfd6db1dd18b1f124cf8abb8709e1f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: f894a027474fa36723db3644d7dc1715dbfd6db1dd18b1f124cf8abb8709e1f8
SHA3-384 hash: dec7e84886052d5b01499b1657ee4f0d131d765ed6935453ce623f405a5f4b4d7d7379b90dcaa0c1f5d24c2cd889f5f1
SHA1 hash: 2daff152cecad77f3a1e5e1d43ee07376fccdabe
MD5 hash: 2e92d20d2ad68d9bd5841910c488af6e
humanhash: coffee-march-magazine-fourteen
File name:2e92d20d2ad68d9bd5841910c488af6e.dll
Download: download sample
Signature TrickBot
File size:1'821'184 bytes
First seen:2021-12-09 16:17:36 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash c131e7ab95b6cc6ff4c2379d5b0fc4ad (3 x TrickBot)
ssdeep 1536:sjkUHInOKVU9vFhgD6wK1LhsfAWs/g9UhwtV/IeQ/HQljEqt:sjFiDgL+C/3hwXfuwJt
TLSH T1C38535F1DBDA8B5FACCC986163020A7A51CA07678D45879AD0BC53FC787D982CC6BC52
Reporter abuse_ch
Tags:dll TrickBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
900
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
DNS request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.CobaltStrike
Status:
Malicious
First seen:
2021-12-09 16:18:12 UTC
File Type:
PE (Sys)
AV detection:
26 of 28 (92.86%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
trickbot
Score:
  10/10
Tags:
family:trickbot botnet:rob142 banker trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Looks up external IP address via web service
Trickbot
Malware Config
C2 Extraction:
181.129.85.98:443
189.112.119.205:443
189.51.118.78:443
186.121.214.106:443
49.176.188.184:443
61.69.102.170:443
213.32.252.221:443
89.46.216.2:443
103.36.79.3:443
103.108.97.51:443
95.140.217.242:443
41.175.22.226:443
190.109.169.161:443
186.159.12.18:443
190.109.171.17:443
181.196.148.202:443
186.47.75.58:443
186.42.212.30:443
190.214.21.14:443
187.108.32.133:443
201.184.226.74:443
186.159.5.177:443
Unpacked files
SH256 hash:
05ecae87363f731b9fcec9363360623d1cfcf3aa896ee816b5e8dcb8920a8d0f
MD5 hash:
6db70a512f482da983511f5acdfd52a2
SHA1 hash:
74e10719aaef9036a92cfb2f5f44f1307516b52c
SH256 hash:
f894a027474fa36723db3644d7dc1715dbfd6db1dd18b1f124cf8abb8709e1f8
MD5 hash:
2e92d20d2ad68d9bd5841910c488af6e
SHA1 hash:
2daff152cecad77f3a1e5e1d43ee07376fccdabe
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

TrickBot

DLL dll f894a027474fa36723db3644d7dc1715dbfd6db1dd18b1f124cf8abb8709e1f8

(this sample)

  
Delivery method
Distributed via web download

Comments