🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba
SHA3-384 hash: f5ef0ffeb906476112c6911eb58d9cd56273645277c60ddade2b09856c8d8c040808013c13f68be93a79b199994aac82
SHA1 hash: 791b293fdbc59b55939cc17d7b61a86785b17ac6
MD5 hash: 4ae812bebf1c3aadd87e6b813cf8fb04
humanhash: glucose-burger-bacon-wisconsin
File name:bicyv.exe
Download: download sample
Signature ZLoader
File size:327'546 bytes
First seen:2020-09-26 06:34:15 UTC
Last seen:2020-09-26 07:34:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ced282d9b261d1462772017fe2f6972b (129 x Formbook, 124 x GuLoader, 72 x RemcosRAT)
ssdeep 3072:Lf1BDZ0kVB67Duw9AMcMUdJKmDbjUpgp7iPxvqKt0VWUJEUnjI+XkeKNud2W46vs:L9X0GrLIpW0vq7AUrI+XEY2IFKp9
TLSH AB6424CB2E4086B7DB1DF27004B7B73C476BA83C6BD34E5EA20B3E4A6B3299D5519141
Reporter Anonymous
Tags:ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Sending a UDP request
Creating a file in the %temp% subdirectories
Creating a file
Unauthorized injection to a recently created process
Deleting a recently created file
Replacing files
Delayed writing of the file
Delayed reading of the file
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.TrickBot
Status:
Malicious
First seen:
2020-09-24 03:49:31 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Loads dropped DLL
Unpacked files
SH256 hash:
0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba
MD5 hash:
4ae812bebf1c3aadd87e6b813cf8fb04
SHA1 hash:
791b293fdbc59b55939cc17d7b61a86785b17ac6
SH256 hash:
dd82133002ac82f1648b81ec5043ad3cf2d9f533ebc01359ba0d79dea648bdfa
MD5 hash:
75a1c82fcf9762bb6e1c0f039d2d222f
SHA1 hash:
ed4279afac8a24975bae33af2fdf3a70dac9da3f
SH256 hash:
f39cac59ba71040ed07497e963a15706e3834526991a3290be9ac004af3f98bc
MD5 hash:
9096cdf5ba4508443e920daee6c33edd
SHA1 hash:
95e8ab31708aae5511737123a7937fe71eb4d67e
Detections:
win_zloader_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments