MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 372bae872e2a2180f04ff14f8fb9f769d733cb4608d37e2bf6e61fee5d396018. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 372bae872e2a2180f04ff14f8fb9f769d733cb4608d37e2bf6e61fee5d396018
SHA3-384 hash: 62902c4c4eee3bb749578f9c9a254888b5cb8da43685d306a98504a66d50029b7a7f111eb4db76cbf4df15ca15cbf64c
SHA1 hash: 8bae4934e78c738ed60f631bc67db34604d35818
MD5 hash: cd39fa1ea4f0c4c9c2dd8492ff597250
humanhash: mockingbird-oven-uniform-yellow
File name:SecuriteInfo.com.ArtemisCD39FA1EA4F0.15336
Download: download sample
Signature ZLoader
File size:457'216 bytes
First seen:2020-04-18 02:40:47 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 4dbdbf8a52661c078b4a242b754db3bf (1 x ZLoader)
ssdeep 6144:t1/Zy7Ge5qC9axTeJNZ/AuVEpsm8uchgwgKFV0HgdLtF23JQUWjlRdvJ:tZ33fiNZI6m4330HQf24dvJ
Threatray 37 similar samples on MalwareBazaar
TLSH B8A4C04C7BDF186CD0126E3241917E63B32EA47917798BE31B549CFA0A91EA01D3E19F
Reporter SecuriteInfoCom
Tags:ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-04-17 19:19:25 UTC
File Type:
PE (Dll)
Extracted files:
2
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ZLoader

DLL dll 372bae872e2a2180f04ff14f8fb9f769d733cb4608d37e2bf6e61fee5d396018

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileW
KERNEL32.dll::GetTempPathA
VERSION.dll::GetFileVersionInfoSizeA
VERSION.dll::GetFileVersionInfoA

Comments