MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc74c4b40c376a9aa78d6ebab83b9542fd1abd4d4800c4a0adfee13c9c58d4ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BuerLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: cc74c4b40c376a9aa78d6ebab83b9542fd1abd4d4800c4a0adfee13c9c58d4ed
SHA3-384 hash: edcbb600b5b15bad2889cab2f3a86938794a068a7ba217474d273edbe8be4a467e06b361e81b410feaee8a0b4383761e
SHA1 hash: 5c98896bd3255283727de869b5220f64cd2bd1dc
MD5 hash: 4937035773c422e3eb6ff8bbb00931d7
humanhash: alaska-oxygen-eight-kitten
File name:1c8260f2d597cfc1922ca72162e1eb3f8272c2d18fa41d77b145d32256c0063d_dump.exe.bin
Download: download sample
Signature BuerLoader
File size:36'864 bytes
First seen:2020-12-02 09:17:19 UTC
Last seen:2020-12-02 10:51:08 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7802a2afdb884b4d1a51c221c6ef5fcd (3 x BuerLoader, 2 x TrickBot)
ssdeep 384:2Md1wVcTN/p7Ff3Yunx02sdYda+12w515JaixQNctxyxQcMmZMIMyDmeU:xdS6TNxJXmdYd52w5HTd7yxRZvMsmP
Threatray 6 similar samples on MalwareBazaar
TLSH B4F26C93749AC476C3202B711F86745292E86E2071B7E2F77A6C1CCC7CB4A5BD72A352
Reporter gN3mes1s
Tags:BuerLoader


Avatar
gN3mes1s
in memory executable from : https://bazaar.abuse.ch/sample/1c8260f2d597cfc1922ca72162e1eb3f8272c2d18fa41d77b145d32256c0063d/

Intelligence


File Origin
# of uploads :
2
# of downloads :
161
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Buerloader
Status:
Malicious
First seen:
2020-12-02 09:18:09 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
cc74c4b40c376a9aa78d6ebab83b9542fd1abd4d4800c4a0adfee13c9c58d4ed
MD5 hash:
4937035773c422e3eb6ff8bbb00931d7
SHA1 hash:
5c98896bd3255283727de869b5220f64cd2bd1dc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments