MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a98d46de3bd022d30b403013cd03c5142cf01341bf18e76e487311a8bbee252. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4a98d46de3bd022d30b403013cd03c5142cf01341bf18e76e487311a8bbee252
SHA3-384 hash: 369bcb0df8eeb601426cc94cd44b33f419a38b8318a8c8e80db3186531d31dc96f618b6d5bea680342cc4039001e40cc
SHA1 hash: 2657375b2058876454d61c4068554d322e33d290
MD5 hash: cd7ddfb4530d889716de37ed4ae339b6
humanhash: bravo-april-oxygen-sodium
File name:B2.dll
Download: download sample
Signature ZLoader
File size:581'120 bytes
First seen:2020-09-09 13:04:05 UTC
Last seen:2020-09-09 13:34:56 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 554b794aa3b7f1489f81aa542a629c82 (1 x ZLoader)
ssdeep 6144:5XhlbaTbLY6VhaQOJz3utQd24SG5MvoNQ/JyRpYrCBa:5Xh5a7BV83utQd248vorRpYz
Threatray 6 similar samples on MalwareBazaar
TLSH 78C4A412F7D71F27CD9B3136845A2CB7817BEE840799FA0746A9B944DAB03E93721207
Reporter JAMESWT_WT
Tags:ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Bsymem
Status:
Malicious
First seen:
2020-09-02 07:13:05 UTC
File Type:
PE (Dll)
Extracted files:
26
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments