MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 61b0aa94dc56585b7255398cd755e9db6fedd5b06ebca386b2dc5fddc8cf5478. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZeuS


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 61b0aa94dc56585b7255398cd755e9db6fedd5b06ebca386b2dc5fddc8cf5478
SHA3-384 hash: 291a24f67def49c3fa931307d04b249d7c92e11b6f5e3a6bb8194ea521d648d22fd251bc67284ede50064fea4acd56db
SHA1 hash: a86e5892bcf3eaed0bdc204ad80ff8bc60f032fe
MD5 hash: 3b997a5a3918b2ae5d7d15ed3b288792
humanhash: iowa-carpet-bacon-sink
File name:zbotya.exe
Download: download sample
Signature ZeuS
File size:141'824 bytes
First seen:2020-04-30 03:33:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f093683b353b2a00aa3c07bc9edf850d (1 x ZeuS)
ssdeep 3072:qzY1LZQEduEgsW2UPqxUEqsbqkC0i50/YXiQXT+t/8XIgfUTaXD3kz1QN8:qzY1L+QHhUPqxUEv5QiQwkXhfUThQe
Threatray 131 similar samples on MalwareBazaar
TLSH 3AD3AF577480E1F3C9EB1272AA69776563FFC93436388C83E3140E6A3575883A25E74B
Reporter adm1n_usa32
Tags:zbot ZeuS


Avatar
adm1n_usa32
Zeus malware.

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'904
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::ConvertSidToStringSidW
ADVAPI32.dll::ConvertStringSecurityDescriptorToSecurityDescriptorW
ADVAPI32.dll::EqualSid
ADVAPI32.dll::GetLengthSid
ADVAPI32.dll::GetSidSubAuthority
ADVAPI32.dll::GetSidSubAuthorityCount
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
DP_APIUses DP APICRYPT32.dll::CryptUnprotectData
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AdjustTokenPrivileges
ADVAPI32.dll::GetTokenInformation
ADVAPI32.dll::IsWellKnownSid
ADVAPI32.dll::SetSecurityDescriptorDacl
ADVAPI32.dll::SetSecurityDescriptorSacl
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteW
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::CreateProcessAsUserW
KERNEL32.dll::CreateRemoteThread
KERNEL32.dll::CreateProcessW
KERNEL32.dll::OpenProcess
ADVAPI32.dll::OpenProcessToken
ADVAPI32.dll::OpenThreadToken
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetCommandLineW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::MoveFileExW
SHLWAPI.dll::PathRemoveFileSpecW
WIN_BASE_USER_APIRetrieves Account InformationKERNEL32.dll::GetComputerNameW
ADVAPI32.dll::LookupPrivilegeValueW
WIN_CRYPT_APIUses Windows Crypt APICRYPT32.dll::CertDeleteCertificateFromStore
CRYPT32.dll::CertDuplicateCertificateContext
CRYPT32.dll::CertEnumCertificatesInStore
CRYPT32.dll::CertOpenSystemStoreW
ADVAPI32.dll::CryptAcquireContextW
ADVAPI32.dll::CryptCreateHash
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExW
ADVAPI32.dll::RegOpenKeyExW
ADVAPI32.dll::RegQueryValueExW
ADVAPI32.dll::RegSetValueExW
WIN_SOCK_APIUses Network to send and receive dataWS2_32.dll::freeaddrinfo
WS2_32.dll::getaddrinfo
WS2_32.dll::WSAAddressToStringW
WS2_32.dll::WSAEventSelect
WS2_32.dll::WSAIoctl
WS2_32.dll::WSASend
WIN_USER_APIPerforms GUI ActionsUSER32.dll::CloseDesktop
USER32.dll::OpenInputDesktop
USER32.dll::PeekMessageA
USER32.dll::PeekMessageW
USER32.dll::CreateWindowStationW

Comments