MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 74bced5451defff3895c5ccb299e5d72f05f64e765472ea746a4d8f6371341ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 74bced5451defff3895c5ccb299e5d72f05f64e765472ea746a4d8f6371341ff
SHA3-384 hash: 8dfb14e3d453629754882abed2d0ef66b6345db9532afc9c4421bb09d2cdaf4c55bf0659ca33969fedba561c4ac0851b
SHA1 hash: 698c1a537f52490ac3df234262855ad13c5c0fdf
MD5 hash: 4a125de0e4331ad7be02c0cda051a793
humanhash: west-ten-may-green
File name:284.exe
Download: download sample
Signature BazaLoader
File size:258'744 bytes
First seen:2020-10-15 16:31:08 UTC
Last seen:2020-10-16 08:58:21 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d5c1175232eccc8f81432751336338f2 (4 x BazaLoader)
ssdeep 3072:/RgMHKGPcPZedN+S+E6AAJP4u1MKueXu4vj7UIgbzjN8vDAJjOsn9oY4rY1aZaM:R5P/Nu54unXd7Ufx+DGxohjaM
Threatray 132 similar samples on MalwareBazaar
TLSH 7D444B04529A5EF6E86383BC4817D312BDF775805718CF6B83B849392E072D63A6DFA1
Reporter James_inthe_box
Tags:BazaLoader exe Rumikon LLC

Code Signing Certificate

Organisation:DigiCert High Assurance EV Root CA
Issuer:DigiCert High Assurance EV Root CA
Algorithm:sha1WithRSAEncryption
Valid from:Nov 10 00:00:00 2006 GMT
Valid to:Nov 10 00:00:00 2031 GMT
Serial number: 02AC5C266A0B409B8F0B79F2AE462577
Intelligence: 204 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 7431E5F4C3C1CE4690774F0B61E05440883BA9A01ED00BA6ABD7806ED3B118CF
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
100
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Sending a custom TCP request
Sending a UDP request
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
5 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.BazarLoader
Status:
Malicious
First seen:
2020-10-15 16:31:01 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Result
Malware family:
bazarbackdoor
Score:
  10/10
Tags:
backdoor family:bazarbackdoor
Behaviour
Modifies system certificate store
BazarBackdoor
Unpacked files
SH256 hash:
74bced5451defff3895c5ccb299e5d72f05f64e765472ea746a4d8f6371341ff
MD5 hash:
4a125de0e4331ad7be02c0cda051a793
SHA1 hash:
698c1a537f52490ac3df234262855ad13c5c0fdf
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments