MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ZLoader
Vendor detections: 7
| SHA256 hash: | 0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba |
|---|---|
| SHA3-384 hash: | f5ef0ffeb906476112c6911eb58d9cd56273645277c60ddade2b09856c8d8c040808013c13f68be93a79b199994aac82 |
| SHA1 hash: | 791b293fdbc59b55939cc17d7b61a86785b17ac6 |
| MD5 hash: | 4ae812bebf1c3aadd87e6b813cf8fb04 |
| humanhash: | glucose-burger-bacon-wisconsin |
| File name: | bicyv.exe |
| Download: | download sample |
| Signature | ZLoader |
| File size: | 327'546 bytes |
| First seen: | 2020-09-26 06:34:15 UTC |
| Last seen: | 2020-09-26 07:34:10 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | ced282d9b261d1462772017fe2f6972b (129 x Formbook, 124 x GuLoader, 72 x RemcosRAT) |
| ssdeep | 3072:Lf1BDZ0kVB67Duw9AMcMUdJKmDbjUpgp7iPxvqKt0VWUJEUnjI+XkeKNud2W46vs:L9X0GrLIpW0vq7AUrI+XEY2IFKp9 |
| TLSH | AB6424CB2E4086B7DB1DF27004B7B73C476BA83C6BD34E5EA20B3E4A6B3299D5519141 |
| Reporter | Anonymous |
| Tags: | ZLoader |
Intelligence
File Origin
# of uploads :
2
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Detection(s):
Result
Verdict:
Suspicious
Maliciousness:
Behaviour
Sending a UDP request
Creating a file in the %temp% subdirectories
Creating a file
Unauthorized injection to a recently created process
Deleting a recently created file
Replacing files
Delayed writing of the file
Delayed reading of the file
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Detection:
zloader
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2020-09-24 03:49:31 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Result
Malware family:
n/a
Score:
7/10
Tags:
n/a
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Loads dropped DLL
Unpacked files
SH256 hash:
0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba
MD5 hash:
4ae812bebf1c3aadd87e6b813cf8fb04
SHA1 hash:
791b293fdbc59b55939cc17d7b61a86785b17ac6
SH256 hash:
dd82133002ac82f1648b81ec5043ad3cf2d9f533ebc01359ba0d79dea648bdfa
MD5 hash:
75a1c82fcf9762bb6e1c0f039d2d222f
SHA1 hash:
ed4279afac8a24975bae33af2fdf3a70dac9da3f
SH256 hash:
f39cac59ba71040ed07497e963a15706e3834526991a3290be9ac004af3f98bc
MD5 hash:
9096cdf5ba4508443e920daee6c33edd
SHA1 hash:
95e8ab31708aae5511737123a7937fe71eb4d67e
Detections:
win_zloader_auto
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trickbot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.