MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e48c6326181bf9fe5cb074a0c7dc955a3e5d23c9f77195e319cf88cafdab447. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3e48c6326181bf9fe5cb074a0c7dc955a3e5d23c9f77195e319cf88cafdab447
SHA3-384 hash: 0fd64caa3f74c1edce6213a3328e407643120653fa46d4c33d798afe1d3aa2fd294fa0852d2cae1ad053d5db3d184b92
SHA1 hash: 7dd8ee0486081a0205ebbeb0ca69b86eae1b268e
MD5 hash: 506825449f3ed2ae90351b756bef2d4c
humanhash: fanta-missouri-april-hotel
File name:506825449f3ed2ae90351b756bef2d4c.exe
Download: download sample
Signature BazaLoader
File size:758'784 bytes
First seen:2020-11-05 06:25:48 UTC
Last seen:2020-11-05 08:10:17 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 474f72f0949d873019b68fa720af8d4c (1 x BazaLoader, 1 x TrickBot)
ssdeep 6144:er6mnswGnrxyhoLYpMhukvKcowXHQ2ndC6KHvj:+6Ss9n9ySLYzXcpXxC6KHb
Threatray 1 similar samples on MalwareBazaar
TLSH 66F4FF18E51A5F3BDDC253ED0A13D12B3CEF239469098F85EA99153A5C092CBA38D7F4
Reporter abuse_ch
Tags:BazaLoader exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
103
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Connection attempt
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Kryptik
Status:
Malicious
First seen:
2020-09-16 08:27:40 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Looks up external IP address via web service
Unpacked files
SH256 hash:
3e48c6326181bf9fe5cb074a0c7dc955a3e5d23c9f77195e319cf88cafdab447
MD5 hash:
506825449f3ed2ae90351b756bef2d4c
SHA1 hash:
7dd8ee0486081a0205ebbeb0ca69b86eae1b268e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments