MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f84e08a4d83f63cb37f7117f401c242ecbd3ebbd6b7a12fb99332bcf5950f803. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f84e08a4d83f63cb37f7117f401c242ecbd3ebbd6b7a12fb99332bcf5950f803
SHA3-384 hash: 230c44576644c40b6bcd7414c7d963d1945bd55c1707bcf7e3fe2aaedfcd9c48016f1cee41e35247db33bc5a59cf2a49
SHA1 hash: 8a1c5a4f794af421e7b54471ed7f4a62212721a0
MD5 hash: 95d3b622d696c1a31dbef624a2e47163
humanhash: golf-wisconsin-queen-romeo
File name:SecuriteInfo.com.BScope.TrojanSpy.Ursnif.27559
Download: download sample
Signature ZLoader
File size:436'224 bytes
First seen:2020-06-26 17:35:07 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 466fe1b5793453f59a8e2089eb4bcb8d (1 x ZLoader)
ssdeep 6144:gJf9uWKIWhnuEbXDcQ/MUF0140znw+i/ZEOEHDLDXRYWQ:g6Jhu0IQ/MUwcDENTQ
Threatray 152 similar samples on MalwareBazaar
TLSH C794AE3E76C0E036D16A423988A9C97445FCBD608B2F874B73C84E2F1E77784566A7D2
Reporter SecuriteInfoCom
Tags:ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-26 17:37:04 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
spyware trojan botnet family:zloader persistence
Behaviour
Suspicious use of WriteProcessMemory
Runs net.exe
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Discovers systems in the same network
Suspicious use of SetThreadContext
Modifies service
Reads user/profile data of web browsers
Blacklisted process makes network request
Zloader, Terdot, DELoader, ZeusSphinx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments