MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31c57541340693e7d17b176c8efef365db760bc80cc8a15fa0359cbd0fa3efa2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BuerLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 31c57541340693e7d17b176c8efef365db760bc80cc8a15fa0359cbd0fa3efa2
SHA3-384 hash: f2f219e260f40ae702f9cda59fe01658c106c6628884d598e15aecf18c09e463332a5be7ef6d3575df731c02f9864901
SHA1 hash: 7426b31ed32d0e2d1d088e4e6ae0f6fdeade9069
MD5 hash: 5cfee7b339cb1b1f510634731328c785
humanhash: massachusetts-earth-glucose-golf
File name:host_dump.exe.bin
Download: download sample
Signature BuerLoader
File size:36'864 bytes
First seen:2020-12-02 09:18:08 UTC
Last seen:2020-12-02 10:51:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7802a2afdb884b4d1a51c221c6ef5fcd (3 x BuerLoader, 2 x TrickBot)
ssdeep 384:FM11MVcTN/97xf3YunxEOIdYda+12w515JaixQNctxyxQkMsMIMyDmKU:21G6TNtNXqdYd52w5HTd7yxJhMsmj
Threatray 6 similar samples on MalwareBazaar
TLSH 56F27D93789AC476C3202B711F85745292E86E2075B7E2F77A6C0CCC7CB4A5BD72A352
Reporter gN3mes1s
Tags:BuerLoader


Avatar
gN3mes1s
in memory executable from : https://bazaar.abuse.ch/sample/b298ead0400aaf886dbe0a0720337e6f2efd5e2a3ac1a7e7da54fc7b6e4f4277/

Intelligence


File Origin
# of uploads :
2
# of downloads :
177
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Buerloader
Status:
Malicious
First seen:
2020-12-02 09:19:07 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
31c57541340693e7d17b176c8efef365db760bc80cc8a15fa0359cbd0fa3efa2
MD5 hash:
5cfee7b339cb1b1f510634731328c785
SHA1 hash:
7426b31ed32d0e2d1d088e4e6ae0f6fdeade9069
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments