MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04ad133967d2076e4ce4cbd04c058ba7e8e3725fb72102e2b1b5de433f44de33. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 04ad133967d2076e4ce4cbd04c058ba7e8e3725fb72102e2b1b5de433f44de33
SHA3-384 hash: 190a62b244c2c2a61deec6d5f9a2be6f89eaae046019fa12d17fb6e7d93b0d0ed2b359bdd5fb81bf38cccccfe854a5a7
SHA1 hash: 30d6a71f832f004e9ca425d74134276c7b29b90b
MD5 hash: ed431245bf44badbb836c8c16478f1c5
humanhash: hotel-summer-friend-avocado
File name:ED431245BF44BADBB836C8C16478F1C5.bin
Download: download sample
Signature BazaLoader
File size:299'696 bytes
First seen:2020-06-22 07:21:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9ecf702fbe39bfec8abdf052311d634f (3 x BazaLoader)
ssdeep 6144:ZwO9Ovf/iwTZ84rl+ETVVI5BwHGEWYgWOt4ps+2J9qUQAd2:ZHa3iI+o45BwHDWY3O+p6/q5
Threatray 255 similar samples on MalwareBazaar
TLSH C354BE3F339428BDDCA76130C9F18546F772742D9339934E07944E6B6E336A1AD2A722
Reporter JAMESWT_WT
Tags:signed

Code Signing Certificate

Organisation:RESURS-RM OOO
Issuer:DigiCert EV Code Signing CA (SHA2)
Algorithm:sha256WithRSAEncryption
Valid from:2020-05-20T00:00:00Z
Valid to:2021-05-13T12:00:00Z
Serial number: 02c5351936abe405ac760228a40387e8
Thumbprint Algorithm:SHA256
Thumbprint: 4301bee92886c02652fa3df8dfde20364015f8986242b176d0e572e72d51d8e0
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win64.Trojan.TrickBot
Status:
Malicious
First seen:
2020-06-18 06:39:00 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
bazarbackdoor
Score:
  10/10
Tags:
backdoor family:bazarbackdoor
Behaviour
BazarBackdoor
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments