🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 38d73ff850a428d03fa32a4cd75f96fc5307c56e8f72290c8dfed375e3faf658. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 38d73ff850a428d03fa32a4cd75f96fc5307c56e8f72290c8dfed375e3faf658
SHA3-384 hash: 4e68c92cde33dda0293596c9186108049d73f6141e77cbd21d796178fdc498a70db9fda8bc2cb506470cc6f6ceec1487
SHA1 hash: f7b5ae69f6b8af075cf41f43495c33392669347b
MD5 hash: 81838b04aed755a29ee12831e0c38d42
humanhash: ceiling-blue-coffee-illinois
File name:eOiF_964.xlsb
Download: download sample
Signature ZLoader
File size:851'351 bytes
First seen:2020-09-02 16:01:26 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 24576:W3AIIiqHzGTmQdfFj2rpeFUgl1/OmGEdZje7CZBDP0:Ww2qHyTVdfFj2rFS/n7E7CZBI
TLSH B505235DF5685A7CC22FA630860BECD689453053AD02306F9C64B246ADED2C376DF72B
Reporter JAMESWT_WT
Tags:ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
DNS request
Sending an HTTP GET request
Sending a custom TCP request by exploiting the app vulnerability
Result
Threat name:
Hidden Macro 4.0
Detection:
malicious
Classification:
spre.troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Contains functionality to inject code into remote processes
Contains VNC / remote desktop functionality (version string found)
Creates a thread in another existing process (thread injection)
Document exploit detected (process start blacklist hit)
Found abnormal large hidden Excel 4.0 Macro sheet
Found Excel 4.0 Macro with suspicious formulas
Found malicious Excel 4.0 Macro
Found obfuscated Excel 4.0 Macro
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Machine Learning detection for dropped file
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Office process drops PE file
Performs a network lookup / discovery via net view
Sigma detected: Microsoft Office Product Spawning Windows Shell
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file access)
Uses ipconfig to lookup or modify the Windows network settings
Uses net.exe to modify the status of services
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 281231 Sample: eOiF_964.xlsb Startdate: 02/09/2020 Architecture: WINDOWS Score: 100 83 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->83 85 Antivirus detection for URL or domain 2->85 87 Antivirus detection for dropped file 2->87 89 13 other signatures 2->89 11 EXCEL.EXE 34 44 2->11         started        process3 dnsIp4 73 thezencon.com 185.201.11.117, 443, 49721, 49722 AS-HOSTINGERLT Germany 11->73 65 C:\Users\user\AppData\Local\...\info[1].png, PE32 11->65 dropped 67 C:\FhUrDOp\XoOXfXf\WINWORD.EXE, PE32 11->67 dropped 69 C:\Users\user\Desktop\~$eOiF_964.xlsb, data 11->69 dropped 101 Document exploit detected (process start blacklist hit) 11->101 16 WINWORD.EXE 11->16         started        file5 signatures6 process7 signatures8 75 Antivirus detection for dropped file 16->75 77 Multi AV Scanner detection for dropped file 16->77 79 Machine Learning detection for dropped file 16->79 81 3 other signatures 16->81 19 msiexec.exe 2 44 16->19         started        process9 dnsIp10 71 lastcost2020.com 217.8.117.105, 49735, 49736, 49737 CREXFEXPEX-RUSSIARU Russian Federation 19->71 63 C:\Users\user\AppData\Roaming\...\bopol.exe, PE32 19->63 dropped 91 Tries to steal Mail credentials (via file access) 19->91 93 Injects code into the Windows Explorer (explorer.exe) 19->93 95 Tries to harvest and steal browser information (history, passwords, etc) 19->95 97 4 other signatures 19->97 24 cmd.exe 1 19->24         started        27 cmd.exe 1 19->27         started        29 explorer.exe 1 19->29 injected 31 2 other processes 19->31 file11 signatures12 process13 signatures14 99 Performs a network lookup / discovery via net view 24->99 47 2 other processes 24->47 49 2 other processes 27->49 33 cmd.exe 1 29->33         started        35 cmd.exe 1 29->35         started        37 cmd.exe 29->37         started        39 net.exe 1 31->39         started        41 ipconfig.exe 1 31->41         started        43 conhost.exe 31->43         started        45 conhost.exe 31->45         started        process15 process16 51 net.exe 1 33->51         started        53 conhost.exe 33->53         started        55 ipconfig.exe 1 35->55         started        57 conhost.exe 35->57         started        59 net1.exe 1 39->59         started        process17 61 net1.exe 1 51->61         started       
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Drops file in Windows directory
Process spawned suspicious child process
Process spawned suspicious child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SharedStrings
Author:Katie Kleemola
Description:Internal names found in LURK0/CCTV0 samples

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments