MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8542bf1c3c7532f11fc39b4b6a20a08ef5bd0c8d42e3262028d4ffdbc5aa88f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8542bf1c3c7532f11fc39b4b6a20a08ef5bd0c8d42e3262028d4ffdbc5aa88f8
SHA3-384 hash: f56258fae43aa9f8aabd2e7948ab7f54930d9a09440cc7b9bc01ecb321b0d6216da746ba8be26163ae2770fbebd5befa
SHA1 hash: 10123cbacb225b078c8e0a847da9e020bc0119e1
MD5 hash: 24f98dee17042e0bd3f723f7bbfa839f
humanhash: video-item-jupiter-sink
File name:VrSiekwRtfHPpfg.dll
Download: download sample
Signature ZLoader
File size:848'896 bytes
First seen:2020-03-31 07:03:36 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 36abf8f3ea4ed429560f2365b3f8de5b (1 x ZLoader)
ssdeep 6144:M7YXX9P2W5pwK9DgomFrmviQwtDkn6xEiMt3BDCmJzwpYPtz7EB3Uk:xYR8viT06jqBD9JzwU9K3U
Threatray 54 similar samples on MalwareBazaar
TLSH 2305E46DA74348E3E7753A34A3C20E52651171D4E8200C8FBBBE2E5C6FA97A27D15EC4
Reporter Racco42
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ZLoader

DLL dll 8542bf1c3c7532f11fc39b4b6a20a08ef5bd0c8d42e3262028d4ffdbc5aa88f8

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA

Comments