MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df69c874357439d92221ea7f9a79eb46ca6672cef5c8fb0029b074166e2a424b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BazaLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: df69c874357439d92221ea7f9a79eb46ca6672cef5c8fb0029b074166e2a424b
SHA3-384 hash: acee16b68cc3666633e8cf176c0fb42c29ef8afed72cf4182138f625812e848739b0bff35816e40d3f0a9657c1e92f4d
SHA1 hash: feca1c63b3b54c9b2c41718eb76af9cd50e357f1
MD5 hash: 5fd0cd5f9cbc6eacb467df234db5c2d5
humanhash: papa-table-summer-queen
File name:53.exe
Download: download sample
Signature BazaLoader
File size:253'952 bytes
First seen:2020-11-02 21:17:23 UTC
Last seen:2020-11-03 06:42:06 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d5c1175232eccc8f81432751336338f2 (4 x BazaLoader)
ssdeep 3072:Mki8vOM7SSgxuu/w4thrSes6UgpYFLBOVtwXTX87VENYJjOsd9oY4wA1a9vsOq:PikuFxuTaPsaYFLoqXiVrboh4vRq
TLSH 03444A04528A5EF6E863937C4817D316BDE775802718CEBB87B4493A2E031D63A6DFE1
Reporter James_inthe_box
Tags:BazaLoader exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
DNS request
Sending a custom TCP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Bazaloader
Status:
Malicious
First seen:
2020-11-02 21:17:08 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
bazarbackdoor
Score:
  10/10
Tags:
family:bazarbackdoor backdoor
Behaviour
Modifies system certificate store
BazarBackdoor
Unpacked files
SH256 hash:
df69c874357439d92221ea7f9a79eb46ca6672cef5c8fb0029b074166e2a424b
MD5 hash:
5fd0cd5f9cbc6eacb467df234db5c2d5
SHA1 hash:
feca1c63b3b54c9b2c41718eb76af9cd50e357f1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments