MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 407efed8e868c0a3e8ef9dfbce26b48bdcd03b80dabdb39fadc4b16094e89bd1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
BazaLoader
Vendor detections: 5
| SHA256 hash: | 407efed8e868c0a3e8ef9dfbce26b48bdcd03b80dabdb39fadc4b16094e89bd1 |
|---|---|
| SHA3-384 hash: | bc27dc04e75965eb0affa73800ef506218f7660f8f4451ccc9b66df842bd297929470f538e194bcc9fe15aba5fcabdb7 |
| SHA1 hash: | a8dd85025daa2ee7ebd21f920745e4ed04d60627 |
| MD5 hash: | 4aa61251226a51e9bdf40487265ab8be |
| humanhash: | xray-queen-yankee-missouri |
| File name: | GVer.dll |
| Download: | download sample |
| Signature | BazaLoader |
| File size: | 1'513'984 bytes |
| First seen: | 2021-03-22 17:52:06 UTC |
| Last seen: | 2021-03-25 14:43:19 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 5a7099f150d97e1a63c112090146d5ac (1 x BazaLoader) |
| ssdeep | 24576:JqM7Hzmp4QRt9iquqVL+1Tth2WrBjSu3SVIrkahXZzQX9SRaNGCEpyaYa3uWwkgJ:2CPuWwkgGa |
| TLSH | E865C786ED5E71E9D4B2F7B5A662F501FCA87A0994B43E108D959E136BB2710F0BC30C |
| Reporter | |
| Tags: | BazaLoader dll |
Intelligence
File Origin
# of uploads :
2
# of downloads :
149
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
form_867710861_1980511489.xls
Verdict:
Malicious activity
Analysis date:
2021-03-22 17:10:34 UTC
Tags:
macros loader
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
BazaLoader
Result
Verdict:
Clean
Maliciousness:
Behaviour
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Detection(s):
Suspicious file
Unpacked files
SH256 hash:
407efed8e868c0a3e8ef9dfbce26b48bdcd03b80dabdb39fadc4b16094e89bd1
MD5 hash:
4aa61251226a51e9bdf40487265ab8be
SHA1 hash:
a8dd85025daa2ee7ebd21f920745e4ed04d60627
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.