MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 534d60392e0202b24d3fdaf992f299ef1af1fb5efef0096dd835fe5c4e30b0fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 534d60392e0202b24d3fdaf992f299ef1af1fb5efef0096dd835fe5c4e30b0fa
SHA3-384 hash: 99c28f97242cffc6d26a255fdcd41932bdbc280cb8f1155f2e4b9b4df03666b6927457c4a04754a71837039e0af8a749
SHA1 hash: e402fb90748df06b77f820d200f75cfa084d680b
MD5 hash: c03f4ea15159222c609ededaddc57968
humanhash: tennessee-five-ceiling-lithium
File name:dave.exe
Download: download sample
Signature BazaLoader
File size:162'291 bytes
First seen:2020-04-17 17:00:50 UTC
Last seen:2020-04-17 17:42:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 266c5adbaf4ad57294d0427a3938e650 (1 x BazaLoader, 1 x TrickBot)
ssdeep 3072:voRdnW3ztcimI473eJdRHEgJbnIDnOuj6v/Mw5K8qa:QfaFmj73eJ0eTIzRyc8
Threatray 71 similar samples on MalwareBazaar
TLSH CBF37C1772A430F8E1769639C8A21A16F3B2783517318B5F07A447762F63660BE3EB52
Reporter James_inthe_box
Tags:BazaLoader exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (GUARD_CF)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW

Comments