| File name: | 998179.exe |
| Full analysis: | https://app.any.run/tasks/bd84b14c-5aed-4739-a0f1-5732552fae76 |
| Verdict: | Malicious activity |
| Threats: | TrickBot is an advanced banking trojan that attackers can use to steal payment credentials from the victims. It can redirect the victim to a fake banking cabinet and retrieve credentials typed in on the webpage. |
| Analysis date: | March 25, 2025, 06:04:36 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 547B7E2B4805D3C310E4652FFACF9C5D |
| SHA1: | 6D0089B6763EEB53325FC28174ED2B4D94212DE5 |
| SHA256: | 4B308D13608D7C435437A78296CF251C05CBEA157CA43BBEC3DD46A8D07C4411 |
| SSDEEP: | 24576:pZLXHqLDh/kZjvNBYnfN6pmmSvKMD2FTXwWXnlc9VUH:pZLXHqLDh/k9vNBmfN6pmrvKMyFrwWXT |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:08:27 14:27:27+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 627200 |
| InitializedDataSize: | 142848 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1cafc |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.3.34.41 |
| ProductVersionNumber: | 3.3.34.41 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Whythousand LogiGear |
| FileDescription: | Excite Blood cle |
| FileVersion: | 3.3.34.41 |
| InternalName: | Excite Blood cle |
| LegalCopyright: | Copyright (c) 2005-2018, Whythousand LogiGear |
| OriginalFileName: | ra.exe |
| ProductName: | Excite Blood cle |
| ProductVersion: | 3.3.34.41 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4040 | C:\WINDOWS\system32\svchost.exe | C:\Windows\System32\svchost.exe | 998199.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
TrickBot(PID) Process(4040) svchost.exe C2 srv (47)185.82.202.89:443 89.105.203.184:443 54.36.28.94:443 178.157.82.90:443 95.181.198.88:443 5.253.63.157:443 107.181.175.122:443 37.228.117.250:443 93.189.44.92:443 95.215.206.34:443 178.170.189.117:443 31.184.253.6:443 5.53.124.49:443 146.185.219.27:443 198.46.198.12:443 190.154.203.218:449 189.80.134.122:449 200.119.45.140:449 191.37.181.152:449 187.58.56.26:449 146.196.122.167:449 177.103.240.149:449 131.196.184.141:449 186.47.40.234:449 103.84.238.3:449 190.152.4.210:449 186.156.52.78:449 36.89.85.103:449 181.176.160.145:449 200.119.45.140:449 190.13.190.178:449 186.46.63.58:449 181.112.159.70:449 181.129.93.226:449 186.42.226.46:449 190.13.160.19:449 186.183.199.114:449 202.9.120.79:449 181.129.140.140:449 103.207.1.44:449 190.151.213.140:449 168.227.229.112:449 186.42.186.202:449 190.152.36.30:449 190.152.38.66:449 181.129.49.98:449 186.47.82.6:449 version1000465 Botnetleo7 KeyRUNTMzAAAADzIIbbIE3wcze1+xiwwK+Au/P78UrAO8YAHyPvHEwGVKOPphl8QVfrC7x/QaFYeXANw6E4HF7ietEp+7ZVQdWOx8c+HvO0Z2PTUPVbX9HAVrg4h9u1RNfhOHk+YysDLsg= Autorun module @namesysteminfo @ctlGetSystemInfo @nameinjectDll @namepwgrab other (201)checkip.amazonaws.com ipecho.net ipinfo.io api.ipify.org icanhazip.com myexternalip.com wtfismyip.com ip.anysrc.net api.ipify.org api.ip.sb ident.me www.myexternalip.com /plain /ip /raw /text /?format=text zen.spamhaus.org cbl.abuseat.org b.barracudacentral.org dnsbl-1.uceprotect.net spam.dnsbl.sorbs.net svchost.exe data\ POST Global\%08lX%04lX%lu Global\First 1066 GetProcAddress kernel32.dll /%s/%s/14/%s/%s/0/ ver.txt SINJ VERS WantRelease ModuleQuery %02X Run D failed Create ZP failed Load to P failed Find P failed Module has already been loaded Launch USER failed Load to M failed ECCPUBLICBLOB Microsoft Software Key Storage Provider Module is not valid info data %s/%s/64/%s/%s/%s/ Data\ %s%s /%s/%s/1/%s/ S-1-5-18 SYSTEM Speed lan library explorer.exe SeTcbPrivilege LeaveCriticalSection EnterCriticalSection InitializeCriticalSection ExitProcess ResetEvent CloseHandle WaitForSingleObject SignalObjectAndWait not listed listed DNSBL client is behind NAT failed NAT status client is not behind NAT %s%s_configs\ /%s/%s/25/%s/ %s %s %s.%s --%s-- --%s
Content-Disposition: form-data; name="%S" Content-Type: multipart/form-data; boundary=%s
Content-Length: %d ------Boundary%08X Register u failed, 0x%x Create xml2 failed Register s failed, 0x%x user Create xml failed pIT GetFolder failed, 0x%x pIT connect failed, 0x%x tmp /%s/%s/10/%s/%s/%d/ D:(A;;GA;;;WD)(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;RC) /%s/%s/23/%d/ SignatureLength ECDSA_P384 .tmp Release FreeBuffer Control Start GET autorun winsta0\default path UrlEscapeW shlwapi WTSQueryUserToken WTSGetActiveConsoleSessionId WTSFreeMemory WTSEnumerateSessionsA wtsapi32 %s.%s.%s.%s /%s/%s/0/%s/%s/%s/%s/%s/ %d%d%d. CI failed, 0x%x </Command>
</Exec>
</Actions>
</Task> </Principal>
</Principals>
<Settings>
<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
<StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
<AllowHardTerminate>false</AllowHardTerminate>
<StartWhenAvailable>true</Sta... </UserId> <UserId> </StartBoundary>
<Enabled>true</Enabled>
</TimeTrigger>
</Triggers>
<Principals>
<Principal id="Author"> %04d-%02d-%02dT%02d:%02d:%02d <TimeTrigger>
<Repetition>
<Interval>PT11M</Interval>
<Duration>P414DT11H23M</Duration>
<StopAtDurationEnd>false</StopAtDurationEnd>
</Repetition>
<StartBoundary> </LogonTrigger> <LogonTrigger>
<Enabled>true</Enabled> </BootTrigger> <BootTrigger>
<Enabled>true</Enabled> <?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
<RegistrationInfo>
<Version>1.0.0</Version>
<Author>AuthorName</Author>
<Description>New speed lan library</Description>
</RegistrationInfo>
<Triggers> <LogonType>InteractiveToken</LogonType>
<RunLevel>LeastPrivilege</RunLevel> <RunLevel>HighestAvailable</RunLevel>
<GroupId>NT AUTHORITY\SYSTEM</GroupId>
<LogonType>InteractiveToken</LogonType> Module already unloaded working Start failed Process has been finished Process was unloaded Unable to load module from server GetParentInfo error Win32 error release start Decode from BASE64 error Invalid params count No params %u %u %u %u settings.ini LoadLibraryW \speedLan Windows Server 2008 R2 Windows Server 2008 Windows Server 2012 R2 Windows Server 2012 %s %s SP%d x86 x64 Unknown Windows 7 Windows 8.1 Windows 8 Windows XP Windows 2000 Windows 10 Server Windows Vista Windows Server 2003 Windows 10 0.0.0.0 Control failed exc E: 0x%x A: 0x%p spk Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3731.0 Safari/537.36 pIT NULL %s sTart /%s/%s/5/%s/ noname %s/%s/63/%s/%s/%s/%s/ <moduleconfig>*</moduleconfig> fifty cmd.exe bcrypt.dll ntdll.dll OLEAUT32.dll IPHLPAPI.DLL ole32.dll USER32.dll ADVAPI32.dll SHLWAPI.dll CRYPT32.dll USERENV.dll SHELL32.dll WINHTTP.dll WS2_32.dll ncrypt.dll C @ = V{D AD o R# PPq >{D B }!O'W8 | |||||||||||||||
| 5404 | "C:\Users\admin\AppData\Roaming\speedLan\998199.exe" | C:\Users\admin\AppData\Roaming\speedLan\998199.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Whythousand LogiGear Integrity Level: SYSTEM Description: Excite Blood cle Exit code: 0 Version: 3.3.34.41 Modules
| |||||||||||||||
| 7256 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7296 | "C:\Users\admin\AppData\Local\Temp\998179.exe" | C:\Users\admin\AppData\Local\Temp\998179.exe | — | dllhost.exe | |||||||||||
User: admin Company: Whythousand LogiGear Integrity Level: HIGH Description: Excite Blood cle Exit code: 0 Version: 3.3.34.41 Modules
| |||||||||||||||
| 7384 | C:\WINDOWS\system32\svchost.exe | C:\Windows\System32\svchost.exe | 998179.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Host Process for Windows Services Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7392 | "C:\Users\admin\AppData\Local\Temp\998179.exe" | C:\Users\admin\AppData\Local\Temp\998179.exe | — | explorer.exe | |||||||||||
User: admin Company: Whythousand LogiGear Integrity Level: MEDIUM Description: Excite Blood cle Exit code: 0 Version: 3.3.34.41 Modules
| |||||||||||||||
| 7416 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7448 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8156 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} | C:\Windows\SysWOW64\dllhost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (8156) dllhost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7384 | svchost.exe | C:\Users\admin\AppData\Roaming\speedLan\998199.exe | executable | |
MD5:547B7E2B4805D3C310E4652FFACF9C5D | SHA256:4B308D13608D7C435437A78296CF251C05CBEA157CA43BBEC3DD46A8D07C4411 | |||
| 4040 | svchost.exe | C:\Users\admin\AppData\Roaming\speedLan\settings.ini | text | |
MD5:EAE20FEDB3454FA0DA079E5278C94E77 | SHA256:D02CA728ABA7EADA727FB86AED5F3EB18E8043CF9CDD606942C319CE2A0A9A2E | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7448 | slui.exe | 20.83.72.98:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7256 | slui.exe | 20.83.72.98:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4040 | svchost.exe | 95.181.198.88:443 | — | Dataline Ltd | RU | unknown |
4040 | svchost.exe | 103.84.238.3:449 | — | Blue Sky Broadband Pvt. Ltd. | IN | malicious |
4040 | svchost.exe | 178.157.82.90:443 | — | MVPS LTD | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
18.31.95.13.in-addr.arpa |
| unknown |
d.8.0.a.e.e.f.b.0.0.0.0.0.0.0.0.5.0.0.0.0.0.8.0.0.3.0.1.3.0.6.2.ip6.arpa |
| unknown |