MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b2f8907da76b79748fc3d05e76fb0002baddca9b9e081c95770e345e8502af4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4b2f8907da76b79748fc3d05e76fb0002baddca9b9e081c95770e345e8502af4
SHA3-384 hash: d0bc8633f44cdd03e8c58df02fd4b1b166c65d4f3cbe1d0c16bc0dd637c299ba76bc8c2cde5cde32ceb75db2cf29dce8
SHA1 hash: 14f814993587906e8e24b710c3cbe5c06798851a
MD5 hash: fc7b58e72a78c221ccfb0832e6defd7e
humanhash: iowa-purple-twelve-uniform
File name:june25.dll
Download: download sample
Signature ZLoader
File size:364'544 bytes
First seen:2020-06-26 09:57:26 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 3e992137b4b72360676077caae312186 (3 x ZLoader)
ssdeep 6144:IOA9EZ9HHOsAFPtetI7AW7JOpoTIXbv6M19HBqxJPVZ5IebbnB:9A9EZrAFPtkI751OnrRbOJ1P
Threatray 211 similar samples on MalwareBazaar
TLSH FA746D2033B5442CF3574B3D88A2C2735999FD82D575BDEF30C12E8B64472D386A9B9A
Reporter JAMESWT_WT
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 00:22:17 UTC
File Type:
PE (Dll)
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
trojan botnet family:zloader
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetThreadContext
Blacklisted process makes network request
Zloader, Terdot, DELoader, ZeusSphinx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments