MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a67bae3dd73789e892b5114a157d992424d367aae11c5fbaa80be639d6dec798. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BumbleBee


Vendor detections: 10


Intelligence 10 IOCs 1 YARA 46 File information Comments

SHA256 hash: a67bae3dd73789e892b5114a157d992424d367aae11c5fbaa80be639d6dec798
SHA3-384 hash: b24feb9b344dc46e77429922fef1db34fa1fba1ebd127cd2c1d1dd3d58a5990f634baf9014bda1cf9e902c8483a5fa88
SHA1 hash: 188a9815f13a97803b76865941b687c21d0e9b4e
MD5 hash: 81684639c9276254f15f8777b9a63bd5
humanhash: south-oven-carpet-comet
File name:a67bae3dd73789e892b5114a157d992424d367aae11c5fbaa80be639d6dec798.msi
Download: download sample
Signature BumbleBee
File size:10'567'680 bytes
First seen:2025-05-20 10:23:04 UTC
Last seen:2025-05-20 15:12:31 UTC
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 196608:eKhpGIqbo0qpUd5fxbN9QZc1GmbL8bdeIlntj/8/VtEEHluJsciz2eo:e+RGdB0ckmcb8IltzpEHseo
TLSH T18EB6331F776CC707C32E7578A5E72450494B9DD243C8F84AD24DF3A82236A70DE987AA
TrID 88.4% (.MST) Windows SDK Setup Transform script (61000/1/5)
11.5% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter JAMESWT_WT
Tags:BUMBLEBEE Dongguan-Shunkaitong-Technology-Co-Ltd msi signed

Code Signing Certificate

Organisation:Dongguan Shunkaitong Technology Co., Ltd.
Issuer:GlobalSign GCC R45 EV CodeSigning CA 2020
Algorithm:sha256WithRSAEncryption
Valid from:2025-04-29T06:57:35Z
Valid to:2026-04-30T06:57:35Z
Serial number: 2495e333dce11d0ec448addb
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: e878af792384f766e6ae51d1678504488eab87491436d9221f52414bf284a52e
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
46.183.184.146:443 https://threatfox.abuse.ch/ioc/1526015/

Intelligence


File Origin
# of uploads :
3
# of downloads :
97
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
shellcode virus blic
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
installer invalid-signature signed
Result
Threat name:
BumbleBee
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Checks if the current machine is a virtual machine (disk enumeration)
Found direct / indirect Syscall (likely to bypass EDR)
Malicious sample detected (through community Yara rule)
Queries BIOS fan information (via WMI, Win32_Fan, often done to detect virtual machines)
Queries random domain names (often used to prevent blacklisting and sinkholes)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses ipconfig to lookup or modify the Windows network settings
Yara detected BumbleBee
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1690991 Sample: RVTools.msi Startdate: 15/05/2025 Architecture: WINDOWS Score: 100 35 xwn7sukhzhbqv.life 2->35 37 u8karkeeu2qtj.life 2->37 39 20 other IPs or domains 2->39 47 Suricata IDS alerts for network traffic 2->47 49 Malicious sample detected (through community Yara rule) 2->49 51 Yara detected BumbleBee 2->51 53 Queries random domain names (often used to prevent blacklisting and sinkholes) 2->53 9 msiexec.exe 74 31 2->9         started        12 msiexec.exe 5 2->12         started        signatures3 process4 file5 31 C:\Users\user\AppData\Local\...\icardagt.exe, PE32+ 9->31 dropped 33 C:\Users\user\AppData\Local\...\version.dll, PE32+ 9->33 dropped 14 icardagt.exe 8 73 9->14         started        18 msiexec.exe 7 9->18         started        21 msiexec.exe 1 9->21         started        process6 dnsIp7 41 rdg0u5n7237r5.life 23.227.193.23, 443, 60846 HVC-ASUS United States 14->41 43 evzftxl2qjfj4.life 188.40.187.139, 443, 60842, 60844 HETZNER-ASDE Germany 14->43 45 2 other IPs or domains 14->45 55 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 14->55 57 Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines) 14->57 59 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 14->59 61 5 other signatures 14->61 23 ipconfig.exe 1 14->23         started        27 C:\Windows\SystemTemp\MSIB966.tmp, PE32 18->27 dropped 29 C:\Windows\SystemTemp\MSIB7CF.tmp, PE32 18->29 dropped file8 signatures9 process10 process11 25 conhost.exe 23->25         started       
Threat name:
Win64.Trojan.Bumbleloader
Status:
Malicious
First seen:
2025-05-15 08:29:35 UTC
File Type:
Binary (Archive)
Extracted files:
396
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
bumblebee
Similar samples:
Result
Malware family:
bumblebee
Score:
  10/10
Tags:
family:bumblebee botnet:grp0002 discovery loader persistence privilege_escalation
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Blocklisted process makes network request
Enumerates connected drives
BumbleBee
Bumblebee family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BumbleBee2024
Author:enzok
Description:BumbleBee 2024
Rule name:Bumblebee_mem
Author:James_inthe_box
Description:Bumblebee loader
Reference:7a2ac6664ef13971ce464676012092befde8f14b0013b2f0f3e21c9051cb45a0
Rule name:bumblebee_v2
Author:Nikolaos 'n0t' Totosis
Description:BumbleBee Payload v2
Rule name:Check_Qemu_Description
Rule name:Check_Qemu_DeviceMap
Rule name:Check_VBox_Description
Rule name:Check_VBox_DeviceMap
Rule name:Check_VBox_Guest_Additions
Rule name:Check_VBox_VideoDrivers
Rule name:Check_VmTools
Rule name:Check_VMWare_DeviceMap
Rule name:Check_Wine
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_SUSPICIOUS_VM_Evasion_MACAddrComb
Author:ditekSHen
Description:Detects executables referencing virtualization MAC addresses
Rule name:INDICATOR_SUSPICIOUS_VM_Evasion_VirtDrvComb
Author:ditekSHen
Description:Detects executables referencing combination of virtualization drivers
Rule name:kleptoparasite
Author:jarcher
Rule name:maldoc_OLE_file_magic_number
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Windows_Trojan_Bumblebee_35f50bea
Author:Elastic Security
Rule name:win_bumblebee
Rule name:win_bumblebee_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.bumblebee.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments