MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5a74d40bc53d9523af5bdb288339c6e01a487c24a05562f248287477852e9a39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5a74d40bc53d9523af5bdb288339c6e01a487c24a05562f248287477852e9a39
SHA3-384 hash: d94422c5f4bab89987acb771f3ca7b5def0ce20353b960c704c641832b3f20220fd32e040cb086a22d82c9b7bc66710e
SHA1 hash: 5c1e850d96a85efeab698bf00effebd926565731
MD5 hash: b7f735b9cd55c1899b7f90149debd28c
humanhash: salami-nine-kansas-johnny
File name:details1610p.xls
Download: download sample
Signature ZLoader
File size:251'904 bytes
First seen:2020-10-16 13:46:22 UTC
Last seen:2020-10-16 15:15:58 UTC
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 3072:ECCpKjn0zSUIIr75My+3PVBJf3wMQJmMgjEs6M1juOpiJUdPf9GMpLXttZw87y0F:BCpqUIIr2p5BXjEAyOpiqnRF3fltjHR
TLSH 0B34233C3DACC294DB82B0755136F929370DDDA3BD8A0F46C615F8A379B8E815A6178C
Reporter ffforward
Tags:#sovietZloader password:777 sovietzloader xls ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Threat name:
Document-Office.Downloader.EncDoc
Status:
Malicious
First seen:
2020-10-16 13:48:07 UTC
AV detection:
16 of 47 (34.04%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Checks processor information in registry
Enumerates system info in registry
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments