Threat Database Trojans Trojan.TrickBot.WA

Trojan.TrickBot.WA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,426
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: May 13, 2026
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.TrickBot.WA
Signature status: No Signature

Known Samples

MD5: a2dd278b567fab0088b6a1d865b4cdf4
SHA1: d22ba55b1f515f80daebc4c4a20b4a24bea8e403
SHA256: DB43F0553DD86B6674A5C925C42719D00FF9E5C76F9E1860E44722F78BCD330C
File Size: 641.54 KB, 641536 bytes
MD5: 5def8c292807f5b6a2610238b2a51cdf
SHA1: 0e224de4ae2639ee11dac5c255aab3c5b4dbb9c9
SHA256: 969712B6C0F42C07F57602D6F2EF1FA0DC7D609C9002CE7D388111C010AAC462
File Size: 641.54 KB, 641536 bytes
MD5: 842c0ec2c16fd14a656b3caa6b0d93fc
SHA1: 0617b24e963b97ba0fa031d09509b05ab06176d5
SHA256: 8A494CF5613A27DE7739D417506A93AA98C51453230F61DE36D18D53E5456D97
File Size: 641.54 KB, 641536 bytes
MD5: 8db11b35c19d20c550ce5a3519a9e1af
SHA1: 3c811dcd58609419d0febfccd7f6c990e7c34c6d
SHA256: 8A9DF6E95AA286399343DA348CBCD7097F3E579F0189016E26A694DBD928370B
File Size: 641.54 KB, 641536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 2,437
Potentially Malicious Blocks: 1,021
Whitelisted Blocks: 1,416
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 x x x x 0 0 0 0 x 0 0 x 0 x x x x x x x x 0 1 x x x x x x x x 0 x x x x x 0 0 0 x 0 0 0 0 x 0 x 0 x 0 0 0 x x 0 1 x x x 1 0 0 0 0 x 0 x x 0 x 0 0 x x x x 0 0 0 x 0 0 0 0 x 0 x 0 0 0 x x x 0 0 0 x 0 x x x x x 0 x x x x x x x 0 0 x x x x x x x x x x 0 0 0 0 x x x x x 0 0 0 x 0 x x x x x x x x x x 0 0 0 0 0 0 x 0 x x x x x x x x x 0 x x 0 0 x 0 x x x 0 0 0 0 x x 0 0 0 x x 0 0 x x 0 x 0 x 0 0 x 0 x 0 0 x x 0 0 x 0 0 0 x 0 0 x 0 0 x x 0 x x 0 x 0 x x 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x 0 0 x x x x 0 0 x x 0 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x x x x 0 x 0 0 0 x 0 x x x 1 0 0 x 0 0 0 x x 0 x x 0 0 x 0 0 0 x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 x 0 x x x x x 0 x 0 0 0 0 0 x 0 0 0 x x 0 0 x 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 x 1 0 0 x 0 x 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 x x x x x x x x 1 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 x 0 0 0 x x 0 x x x x x x x 0 0 x x x 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x x x x x 0 x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 0 x 0 x 0 x 0 x x x x x x x x x x 1 0 x x x x 0 0 0 x x x x x x x x x x x 0 x x x x x 0 0 0 0 0 0 x x x x 0 0 0 x 0 x x 0 x x x 0 x x x 0 x 1 x x x x 0 0 x x x x x 0 x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x 0 0 x x x x x 0 x x x x 0 x x x x x x x x x x x 0 0 x 0 x x x x x 0 0 x x x x x 0 x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x x 0 0 0 0 x x 0 x x 0 x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x 0 x x x x x 0 x x 0 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x 0 x x x 0 0 x 0 x x x x x x 0 x 0 0 x x 0 0 x x x 0 x 0 x x x x x x x 0 0 0 x 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x 0 0 x x x x x x x x x x x x 0 x x x x x 0 0 x x x x 0 x 1 x 0 x x x 0 x x x 0 x x x x x x x x x x x x x x 0 x 0 0 0 x x x x x x x x 1 x x x x x x x x x x x x x x x x 1 x 0 x 0 x x 0 x 0 0 x x 1 x x x 0 x x x x 0 0 x x 0 x x x x x x x x 0 x x x x x x x x x x x x 0 x 0 x x 0 x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 x 0 x x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • TrickBot.WA

Files Modified

File Attributes
c:\avira Synchronize,Write Attributes
c:\avira\systemupdate.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\avira\systemupdate.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\run::rmc-qg38lr "\Avira\SystemUpdate.exe" RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\explorer\run::rmc-qg38lr "\Avira\SystemUpdate.exe" RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserName
  • GetUserObjectInformation
  • OpenClipboard
Other Suspicious
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • ReadProcessMemory
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • getaddrinfo
  • socket