MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 3 File information Comments

SHA256 hash: 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
SHA3-384 hash: 8a4646ff1171d53373024b7eae79d07300ebf94766523fc34e1ab9a008544d31c07acbbdec8a60017071548065b77dec
SHA1 hash: 148c0cde4f2ef807aea77d7368f00f4c519f47ef
MD5 hash: ced47b89212f3260ebeb41682a4b95ec
humanhash: glucose-social-texas-nebraska
File name:BdApiUtil64.sys
Download: download sample
File size:116'800 bytes
First seen:2025-12-06 17:28:42 UTC
Last seen:Never
File type: sys
MIME type:application/x-dosexec
imphash 1b38467bccadb1f8182353cca9fee8ea
ssdeep 768:0MdM/AcPDiFhlPqbgKq0qC9bheG8FHrtjBUQEEt11l11e6O6yKo/Jqq0nGxobqkD:0LShhKYSdgpjNEEaB0BEj+9QvUb4obB
TLSH T171B3D598D3315286D85B8272C9526791BF70F3707361E39F829251BE1D47FEB1EBA208
TrID 56.5% (.EXE) Win64 Executable (generic) (10522/11/4)
11.0% (.ICL) Windows Icons Library (generic) (2059/9)
10.9% (.EXE) OS/2 Executable (generic) (2029/13)
10.7% (.EXE) Generic Win/DOS Executable (2002/3)
10.7% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter juroots
Tags:signed sys

Code Signing Certificate

Organisation:Baidu Online Network Technology (Beijing)Co., Ltd
Issuer:VeriSign Class 3 Code Signing 2010 CA
Algorithm:sha1WithRSAEncryption
Valid from:2012-04-24T00:00:00Z
Valid to:2015-04-24T23:59:59Z
Serial number: 3bdb1994b98bbb19ab55a42337fa4f5c
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: f5b45c946e10304da7c1c6cb7d84c1348064df5c0ca2065fb602c634f6800a2a
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-debug expired-cert microsoft_visual_cc signed
Verdict:
Malicious
Labled as:
Win64/Baidu.D potentially unsafe application
Verdict:
Clean
File Type:
PE
First seen:
2014-09-03T09:30:00Z UTC
Last seen:
2025-12-06T17:55:00Z UTC
Hits:
~100
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2014-11-01 02:20:42 UTC
File Type:
PE+ (Sys)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sys 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428

(this sample)

  
Delivery method
Distributed via web download

Comments