MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a947c216ea52ce23457b3babb1e1eb6275cabe2150d3995553e4de4b8c3d97f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a947c216ea52ce23457b3babb1e1eb6275cabe2150d3995553e4de4b8c3d97f4
SHA3-384 hash: d4a7a7dd3c1887bb0ce7f1f2d131bcdecc3db8a0e4a70ba9d5ad64780a83594f19abbae95d6a6a5efcfcccf93e5a9227
SHA1 hash: f3a25627f925390097a64a84ef34c952fe8af036
MD5 hash: afdf2fbc0756ed304d1a33083a5f2b0f
humanhash: kansas-lemon-kansas-virginia
File name:antiamsi.bin
Download: download sample
Signature ZLoader
File size:330'752 bytes
First seen:2020-04-21 17:56:22 UTC
Last seen:2020-04-21 19:55:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d01c1de5b3809b46e3c55481ecafaf4f (1 x ZLoader)
ssdeep 6144:vG9T0nIO6C3XwbT5QOIJSeEY7EkvBeC1G:HIO6TTeO8Sw7Ekv8C
Threatray 85 similar samples on MalwareBazaar
TLSH 2C64AF12A6B1B432F2B349355A71A6A6493B7C625F30D18B1FA0EE5F3E353D1C632712
Reporter abuse_ch
Tags:exe ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
111
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-04-21 18:13:42 UTC
File Type:
PE (Exe)
Extracted files:
55
AV detection:
27 of 31 (87.10%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ZLoader

Executable exe a947c216ea52ce23457b3babb1e1eb6275cabe2150d3995553e4de4b8c3d97f4

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::RevertToSelf
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::OpenProcess
KERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::FindFirstVolumeMountPointA
KERNEL32.dll::FindNextVolumeA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::WriteConsoleOutputCharacterW
KERNEL32.dll::PeekConsoleInputW
KERNEL32.dll::SetConsoleOutputCP
KERNEL32.dll::SetConsoleScreenBufferSize
KERNEL32.dll::SetConsoleTextAttribute
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::GetWindowsDirectoryA
ADVAPI32.dll::BackupEventLogA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegQueryMultipleValuesW
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.dll::QueryServiceLockStatusW

Comments