MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4294a73a1d708f475bc957ed10e04b6dbfb238a50a963c0a5393f35bcd9d9d7e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 4294a73a1d708f475bc957ed10e04b6dbfb238a50a963c0a5393f35bcd9d9d7e
SHA3-384 hash: 92400c5eac374d2626f24962d8c3620b1c2045006353ec68aa7f341706738fbe371167df41724745aa05fad4e8f44b6d
SHA1 hash: ad7efb2e94629c79794ac0074ae49ab94d612b9c
MD5 hash: e8fdb64b84efa1ceec8c55321126efa2
humanhash: video-zebra-edward-tennessee
File name:322.exe
Download: download sample
Signature BazaLoader
File size:165'888 bytes
First seen:2020-10-26 14:29:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d7fde2c86f22b444d8f9158d72154c65 (1 x BazaLoader)
ssdeep 3072:RND4v/y/EO44BP846S0t5FbX8h1DHspXRVB:RNTDB76h3X8s7
Threatray 185 similar samples on MalwareBazaar
TLSH 6DF36B0AB25626FAD56383B84C22821AFFB775601B148FDF436407356E262D57E3DFA0
Reporter James_inthe_box
Tags:BazaLoader exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Transferring files using the Background Intelligent Transfer Service (BITS)
DNS request
Sending a custom TCP request
Sending a UDP request
Launching cmd.exe command interpreter
Unauthorized injection to a system process
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 305146 Sample: 322.exe Startdate: 26/10/2020 Architecture: WINDOWS Score: 48 19 Multi AV Scanner detection for submitted file 2->19 6 322.exe 14 2->6         started        9 322.exe 2->9         started        process3 dnsIp4 15 uiyplk.xyz 54.236.241.94, 443, 49727, 49729 AMAZON-AESUS United States 6->15 17 192.168.2.1 unknown unknown 6->17 11 WerFault.exe 20 9 6->11         started        13 cmd.exe 6->13         started        process5
Threat name:
Win64.Trojan.BazarLoader
Status:
Malicious
First seen:
2020-10-26 14:28:55 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Result
Malware family:
bazarbackdoor
Score:
  10/10
Tags:
backdoor family:bazarbackdoor
Behaviour
Modifies system certificate store
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Blacklisted process makes network request
BazarBackdoor
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments