MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 38cf92de5c97f9f79ddfb5632ac92f2670f3aa25414943735ddbe24507ad49f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 38cf92de5c97f9f79ddfb5632ac92f2670f3aa25414943735ddbe24507ad49f3
SHA3-384 hash: 39e1f073c82dfe6c3cf027a0c996ef7e55f827f5ae4a1d9ad4bf18ec95f79725b285896028ee58383022687311bb1bdf
SHA1 hash: b151b9bbe811e62d691b9f963727b0ed47b76131
MD5 hash: 6b846d45f4aabb9a4d19c17fbf5b3f28
humanhash: low-low-don-delaware
File name:Documents-17.iso
Download: download sample
Signature BazaLoader
File size:743'424 bytes
First seen:2022-01-21 19:52:33 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:gsX751Gmi1hcU6g7zCJnTBUxJmODHLU8sE/ATmThxpB9PHP5tT1:Xr58blp7zCWXLUMlTL9PRt1
TLSH T1BCF44A0666A840D4E567B138B51FC616D771BC2F0BB1834B03A8FE7E6F336614E2AB15
Reporter Anonymous
Tags:BazaLoader iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
521
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
greyware keylogger print.exe shell32.dll
Result
Verdict:
MALICIOUS
Threat name:
Win64.Trojan.Reflo
Status:
Malicious
First seen:
2022-01-21 19:53:11 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
2 of 43 (4.65%)
Threat level:
  5/5
Result
Malware family:
bazarloader
Score:
  10/10
Tags:
family:bazarloader dropper loader
Behaviour
Suspicious use of SetWindowsHookEx
Bazar/Team9 Loader payload
Bazar Loader
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments