MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 740577fb4e542f8f73b104ecf8e6890fc5ee3842f5393a9ce728117b11e7d7b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 740577fb4e542f8f73b104ecf8e6890fc5ee3842f5393a9ce728117b11e7d7b3
SHA3-384 hash: b9c0ebae034de8292598d00cbb54beafc68a989dfff443a0f1aca59aaa50d5a3f1280e95b09766f7cbc53eb727476c44
SHA1 hash: 8514083fb1fbd97b2952488b28bd33a8cf9e5ae1
MD5 hash: 6603210c0c8469f9f015d36b0a6373fa
humanhash: five-potato-eight-earth
File name:ufvou.dll
Download: download sample
Signature ZLoader
File size:631'808 bytes
First seen:2020-09-11 21:02:12 UTC
Last seen:2020-09-11 21:35:46 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 07b6064df23980925e9d44c51c5dbfdb (1 x ZLoader)
ssdeep 12288:kBqaKwi+Ibvb/dH2bSe+yxLKRP6OwTrWyUtncz9:80BHA9aP6LTOm9
Threatray 1 similar samples on MalwareBazaar
TLSH 34D4AD217526C4B9D2F641B8DD88C6FD4829BD16CDE17E877AC07F1F30311A0D2AB96A
Reporter malware_traffic
Tags:dll Silent_Night ZLoader


Avatar
malware_traffic
Run method regsvr32.exe /s [filename]

Intelligence


File Origin
# of uploads :
2
# of downloads :
151
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
A
b
c
d
e
f
i
l
M
n
o
r
S
t
u
V
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Zeus
Status:
Malicious
First seen:
2020-09-11 21:04:06 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
21 of 28 (75.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
zloader
Result
Malware family:
zloader
Score:
  10/10
Tags:
trojan botnet family:zloader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Blacklisted process makes network request
Suspicious use of NtCreateUserProcessOtherParentProcess
Zloader, Terdot, DELoader, ZeusSphinx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments