MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7af7f0a46e466b448270f959f4e1a3af964d22b609100536703e299d7618bf2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7af7f0a46e466b448270f959f4e1a3af964d22b609100536703e299d7618bf2d
SHA3-384 hash: 76cb12c89d2f8f9386f280adc51e9649b36f61660e159e437e83b90e8158f00fc5ddbc9c8e964bd70056d3eaf4609ec2
SHA1 hash: f327847059784ce84e92a10098eb979daf5f317b
MD5 hash: 67dbc292bf899109f44e52fa3b9d2a3e
humanhash: thirteen-football-ink-apart
File name:fWpzyAgQmxvltIt.dll
Download: download sample
Signature ZLoader
File size:861'184 bytes
First seen:2020-04-09 12:20:18 UTC
Last seen:2020-04-09 12:45:38 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 4789523dc9305e1d49121ae505d5c6ee (1 x ZLoader)
ssdeep 6144:W7QlAs+ip9I/zzaKO2lbVgqs4zaN0QpJj63gKKZceGbJzCaH0u80EN06:OsJZK9fs4uNbJGgKKiJz/q040
Threatray 34 similar samples on MalwareBazaar
TLSH CA05F75BAF4388F3E3752A3FA6C2190251143595E4E0198FB67DEE1D6E78EA27C01EC4
Reporter Racco42
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ZLoader

DLL dll 7af7f0a46e466b448270f959f4e1a3af964d22b609100536703e299d7618bf2d

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User Authorizationadvapi32.dll::ConvertStringSecurityDescriptorToSecurityDescriptorW
advapi32.dll::SetSecurityInfoExA
COM_BASE_APICan Download & Execute componentsole32.dll::CoGetCallContext
oleacc.dll::DllCanUnloadNow
oleacc.dll::DllUnregisterServer
MULTIMEDIA_APICan Play Multimediaole32.dll::DllGetClassObject
SHELL_APIManipulates System Shelladvapi32.dll::GetLocalManagedApplications
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA
kernel32.dll::GetDriveTypeW
WIN_BASE_EXEC_APICan Execute other programskernel32.dll::GetConsoleNlsMode
kernel32.dll::LoadModule
WIN_BASE_IO_APICan Create Filesversion.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoSizeW
WIN_BCRYPT_APICan Encrypt Filesadvapi32.dll::DecryptFileA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegDisablePredefinedCache
advapi32.dll::RegUnLoadKeyW
WIN_SVC_APICan Manipulate Windows Servicesadvapi32.dll::EnumDependentServicesA

Comments