MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 143bef370f492f0928f56505099c902d6e959e2877e804283df35bd98edddd32. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZeuS


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 143bef370f492f0928f56505099c902d6e959e2877e804283df35bd98edddd32
SHA3-384 hash: 64aec10b70f9bddc9adbb03e6fbe67a81958f00bdacd1194e3d64468e38f5fbf8202d94c5411d6e4aa5f820728853988
SHA1 hash: d8a9b119449bfde31692458e4b13434e42340a31
MD5 hash: 5aedf8b74786a8a7fe704d2036be5daa
humanhash: nebraska-muppet-zebra-virginia
File name:zeusaes_2.7.6.9.vir
Download: download sample
Signature ZeuS
File size:182'784 bytes
First seen:2020-07-19 17:17:37 UTC
Last seen:2020-07-19 19:14:17 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 6d633f113d86c96e25af5fac74040e02 (1 x ZeuS)
ssdeep 3072:MA0D8J9qaD6eU4tymwCPLnV/q8qNPEhOHR6DsDhcuby:tgTanYmwCT8XEE6Ds+o
Threatray 1'776 similar samples on MalwareBazaar
TLSH 3004E045B80C5657E88B1AFE2DC40F1E43E9EC3A7B4145E39E902D96EE270CF5C316A5
Reporter tildedennis
Tags:ZeuS zeusaes


Avatar
tildedennis
zeusaes version 2.7.6.9

Intelligence


File Origin
# of uploads :
2
# of downloads :
116
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Connection attempt to an infection source
Threat name:
Win32.Trojan.Zeus
Status:
Malicious
First seen:
2013-01-28 20:19:00 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of UnmapMainImage
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Adds Run key to start application
Deletes itself
Loads dropped DLL
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments