MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 835048e00ba3babf6f920c9a4c2863865a5dcf8e0b6ede4f57c63aeb9cb5c147. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 835048e00ba3babf6f920c9a4c2863865a5dcf8e0b6ede4f57c63aeb9cb5c147
SHA3-384 hash: 177071f65579b7c65977b9f7202d84037d2abf7ea9aca7af1f402d03696cc897c3cf3197d8a41d7187da8569e701b96a
SHA1 hash: d8143cf09bff7b0ca2a0c777912746a5922104ee
MD5 hash: c844efe1b7e76cbdea36ce62ff788de9
humanhash: summer-vegan-potato-violet
File name:1_02120000.bin
Download: download sample
Signature ZLoader
File size:188'416 bytes
First seen:2020-04-25 20:47:24 UTC
Last seen:2020-04-25 21:45:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash aeaf05baf5176b03e6ca1c1b0c09e695 (2 x ZLoader)
ssdeep 3072:brenHphylBa5vbUVmpg+Rrf17JhNO429gs6F4FO7MvA+lVJeTf7ko2bCHkMwGAkI:UglEzu+pxJhNC9gsxFO7idlzaQo2bVlt
Threatray 85 similar samples on MalwareBazaar
TLSH 0B0418056450C130FD11017169ADF7BE8C6EC22E3B12A6EBCB91C9A09FDC6B476BD25E
Reporter johannes
Tags:ZLoader


Avatar
viql
This is the manually unpacked sample of afdf2fbc0756ed304d1a33083a5f2b0f

Intelligence


File Origin
# of uploads :
2
# of downloads :
110
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ZLoader

Executable exe 835048e00ba3babf6f920c9a4c2863865a5dcf8e0b6ede4f57c63aeb9cb5c147

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleOutputCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::GetFileAttributesW
KERNEL32.dll::GetTempPathA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuW
USER32.dll::CreateMenu
USER32.dll::CreateWindowExW

Comments