🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 034f61d86de99210eb32a2dca27a3ad883f54750c46cdec4fcc53050b2f716eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 034f61d86de99210eb32a2dca27a3ad883f54750c46cdec4fcc53050b2f716eb
SHA3-384 hash: b72f74cf364e6ca02448a5eb9b52059ab787e28ec0ef9264f1811f73264518ef21f9b266b7e198fe5e7d043fa16bece3
SHA1 hash: 2c0bc274bc2fd9dab82330b837711355170fc606
MD5 hash: 1b4eb327a40a14ac4afa627125b63056
humanhash: whiskey-nitrogen-stairway-triple
File name:us12.23.dll
Download: download sample
Signature ZLoader
File size:2'000'152 bytes
First seen:2022-01-06 10:54:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 390c35295acc4905e00281b96bbc6ebe (1 x ZLoader)
ssdeep 6144:V4q0V4Ug/4BxEr3xKveRQNOAGlcrDZqnNrMfBvxknHaK7:VR0mbADE9NfAGlyZuAS7
TLSH T12F952A3C1A7201C4EFE699BBD0446ECA67159F3D759CA985BD383FE2C1787404036AAB
File icon (PE):PE icon
dhash icon 14a993064e93b304 (1 x ZLoader)
Reporter JoulK
Tags:dll exe ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
280
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
us12.23.dll
Verdict:
No threats detected
Analysis date:
2022-01-06 11:00:30 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a file in the %temp% directory
Delayed reading of the file
DNS request
Delayed writing of the file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
greyware keylogger overlay packed
Result
Threat name:
ZLoader
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Found potential dummy code loops (likely to delay analysis)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Yara detected ZLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 548733 Sample: us12.23.dll Startdate: 06/01/2022 Architecture: WINDOWS Score: 80 19 asdfghdsajkl.com/gate.php unknown unknown 2->19 21 daksjuggdhwa.com/gate.php unknown unknown 2->21 23 8 other IPs or domains 2->23 27 Found malware configuration 2->27 29 Multi AV Scanner detection for submitted file 2->29 31 Yara detected ZLoader 2->31 33 3 other signatures 2->33 8 loaddll32.exe 3 2->8         started        signatures3 process4 process5 10 cmd.exe 1 8->10         started        12 regsvr32.exe 2 8->12         started        14 rundll32.exe 2 8->14         started        process6 16 rundll32.exe 2 10->16         started        signatures7 25 Found potential dummy code loops (likely to delay analysis) 16->25
Threat name:
Win32.Downloader.Zload
Status:
Malicious
First seen:
2021-12-14 02:52:00 UTC
File Type:
PE (Dll)
Extracted files:
132
AV detection:
27 of 43 (62.79%)
Threat level:
  3/5
Verdict:
unknown
Result
Malware family:
zloader
Score:
  10/10
Tags:
family:zloader botnet:9092us campaign:9092us botnet trojan
Behaviour
Suspicious use of WriteProcessMemory
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
https://asdfghdsajkl.com/gate.php
https://lkjhgfgsdshja.com/gate.php
https://kjdhsasghjds.com/gate.php
https://kdjwhqejqwij.com/gate.php
https://iasudjghnasd.com/gate.php
https://daksjuggdhwa.com/gate.php
https://dkisuaggdjhna.com/gate.php
https://eiqwuggejqw.com/gate.php
https://dquggwjhdmq.com/gate.php
https://djshggadasj.com/gate.php
Unpacked files
SH256 hash:
e910ef4e08dc88f91a346f102cf7dce1444ed293a7d80602735abda2bc7b4720
MD5 hash:
ef4aa2c37b42d75b0fdc8267826448d3
SHA1 hash:
499e407f3355b6bd7833f9029e6943cee225e881
SH256 hash:
034f61d86de99210eb32a2dca27a3ad883f54750c46cdec4fcc53050b2f716eb
MD5 hash:
1b4eb327a40a14ac4afa627125b63056
SHA1 hash:
2c0bc274bc2fd9dab82330b837711355170fc606
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments