MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a81932797aa7e6324dc3390718163035c75620e6a0fa29c146c13c33b654a283. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a81932797aa7e6324dc3390718163035c75620e6a0fa29c146c13c33b654a283
SHA3-384 hash: e9b85b5e5dc28cd05c54987eadc19708428adb421da726e0869403001dcd9927b0108cae291b9622a3966f80daba103a
SHA1 hash: 0ae5a82e4924a8f9c9f54a862b1e55a47bcf444a
MD5 hash: 03bf6ae76260053a439ba0494240dba1
humanhash: whiskey-robin-uncle-football
File name:ubrsOd.bin
Download: download sample
Signature ZLoader
File size:398'336 bytes
First seen:2020-06-23 14:54:09 UTC
Last seen:2020-06-23 16:05:15 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 1e347652aec90851f7666f043db51c1d (1 x ZLoader)
ssdeep 12288:tCH0RVgW3KQ6XDPD2XI9Qo2nKvTLa864i0U1:zsBpXDPpySLa86lt1
Threatray 134 similar samples on MalwareBazaar
TLSH 9284F110BE42E13ED21BE079C806C5FCDA2D7C556E78189B31DD8F8F7A133528A7895A
Reporter JAMESWT_WT
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.ZLoader
Status:
Malicious
First seen:
2020-06-23 14:56:05 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
trojan botnet family:zloader
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetThreadContext
Zloader, Terdot, DELoader, ZeusSphinx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments