MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f28dd082013ee7df2f5956c4e8791e863e575aa64071af9a910826bc12d27acb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f28dd082013ee7df2f5956c4e8791e863e575aa64071af9a910826bc12d27acb
SHA3-384 hash: b653db192298ee118f03700518976df02280064e58017d4a4fea525902025c13c2b4f16ba7e268feb455c3c19efa3bf3
SHA1 hash: 71fac1254ea1757a88f76a589a575b5e7ba011e9
MD5 hash: 89fbc889caf9e9015b1ee438d1e2f907
humanhash: colorado-victor-monkey-king
File name:9TE15
Download: download sample
Signature ZLoader
File size:443'904 bytes
First seen:2020-07-07 06:02:34 UTC
Last seen:2020-07-07 07:22:32 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 3ba5dd5c0057c3e61e8cd6064bd82e70 (2 x ZLoader)
ssdeep 12288:PF97AxDkxD6uUv2YqefbQzLcvBw1Ux1lXU1lOFo7t:+cDuvvqqQzDWXUvxt
Threatray 128 similar samples on MalwareBazaar
TLSH 2894C1223FD2C475F2AF5F3E8829C571891CBD895A3C58EB12E2A647177718381B8E17
Reporter JAMESWT_WT
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a window
Threat name:
Win32.Trojan.ZLoader
Status:
Malicious
First seen:
2020-07-07 06:04:05 UTC
File Type:
PE (Dll)
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
trojan botnet family:zloader evasion spyware
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetThreadContext
Modifies system certificate store
Blacklisted process makes network request
Zloader, Terdot, DELoader, ZeusSphinx
Suspicious use of NtCreateUserProcessOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments