MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0798aa9b84cfc0805ba08d1c190d1f94edb3f2d1988eb6d6307b1af950e3d75b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZeuS


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 0798aa9b84cfc0805ba08d1c190d1f94edb3f2d1988eb6d6307b1af950e3d75b
SHA3-384 hash: e579da2b9432076cff9ba8fbc932263786114c7656b3f75c1565c38c5ae4574674d33d02ad470d8cc8018149a6c564d9
SHA1 hash: 7ccac9a21cf37b70dac4fc80e08b75494cddbd4c
MD5 hash: c5d14d1402090f41775019e8dd827194
humanhash: orange-william-asparagus-nebraska
File name:0798aa9b84cfc0805ba08d1c190d1f94edb3f2d1988eb6d6307b1af950e3d75b.bin
Download: download sample
Signature ZeuS
File size:198'656 bytes
First seen:2022-04-30 01:34:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d9f30dfacbc21d523f6bb324c4b8c92b (1 x ZeuS)
ssdeep 3072:d7BfivAzBm1SJXLSasN2fKVOAIOXEwyhPjVwp760FdakoDwnGkT+QcOkJQqBv:hBh85D2CO/dNI76KakooL1qt
TLSH T18314D0D3F6E38132F4BB057211332B2BCD76BB202A76C05E6A917D8A5F31751A526393
TrID 45.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.3% (.EXE) OS/2 Executable (generic) (2029/13)
18.0% (.EXE) Generic Win/DOS Executable (2002/3)
18.0% (.EXE) DOS Executable Generic (2000/1)
File icon (PE):PE icon
dhash icon 418f386454574f3e (2 x ZeuS)
Reporter tildedennis
Tags:exe prg ZeuS


Avatar
tildedennis
prg version 1

Intelligence


File Origin
# of uploads :
1
# of downloads :
611
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
0798aa9b84cfc0805ba08d1c190d1f94edb3f2d1988eb6d6307b1af950e3d75b.bin
Verdict:
Suspicious activity
Analysis date:
2022-04-30 01:37:30 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Creating a file in the Windows subdirectories
Unauthorized injection to a system process
Enabling autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive greyware jorik overlay packed remote.exe zbot
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes memory attributes in foreign processes to executable or writable
Creates an undocumented autostart registry key
Found evasive API chain (may stop execution after checking mutex)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file has nameless sections
Writes to foreign memory regions
Yara detected Zues
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Zeus
Status:
Malicious
First seen:
2022-04-27 10:41:11 UTC
File Type:
PE (Exe)
Extracted files:
8
AV detection:
40 of 42 (95.24%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Drops file in System32 directory
Modifies WinLogon
Modifies WinLogon for persistence
Unpacked files
SH256 hash:
0798aa9b84cfc0805ba08d1c190d1f94edb3f2d1988eb6d6307b1af950e3d75b
MD5 hash:
c5d14d1402090f41775019e8dd827194
SHA1 hash:
7ccac9a21cf37b70dac4fc80e08b75494cddbd4c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments