MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 29c222f82d9db373ee755ac832c22540afb8f8708eafe8e96266a02b80759066. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 29c222f82d9db373ee755ac832c22540afb8f8708eafe8e96266a02b80759066
SHA3-384 hash: 3e059902c31a5e5c34467110abcc3dae7da03950ede4499d655653d60d4e8970f7abe5bd25528d43be4159d01cce1867
SHA1 hash: 215d95b1a870433e9f66258ea2f6817012a25de9
MD5 hash: f8bd4440f8d9ca9cbdd6713049821bd2
humanhash: failed-nineteen-salami-mirror
File name:SecuriteInfo.com.Win32.Kryptik.HEJP.2172
Download: download sample
Signature ZLoader
File size:438'272 bytes
First seen:2020-06-25 07:39:54 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 17ee6e09b5f00510f37ad8d45cebe40b (7 x ZLoader)
ssdeep 6144:qI/OgKQiC3xpdHtZDumjwb3ID97g+48vlDoTjfIVNqUC1FqsorJTg:qIFzBp1tZDuFb4DNg+Rt0Y9k
Threatray 156 similar samples on MalwareBazaar
TLSH 9B948E2037A6042FF377473C88EAC1B18A9CBD429470BDDB31C26D4B09576D396A9B5B
Reporter SecuriteInfoCom
Tags:ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Gathering data
Result
Malware family:
zloader
Score:
  10/10
Tags:
trojan botnet family:zloader evasion spyware persistence
Behaviour
Discovers systems in the same network
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetThreadContext
Modifies service
Modifies system certificate store
Reads user/profile data of web browsers
Blacklisted process makes network request
Zloader, Terdot, DELoader, ZeusSphinx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments