MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7d5ef8e6c5738ebc13718eee67f0b6cc354f3e28b135e4a378f69d57043299b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 7d5ef8e6c5738ebc13718eee67f0b6cc354f3e28b135e4a378f69d57043299b8
SHA3-384 hash: fd720a298538e2b15bb4521a4c8feea210ac777254270a92afafd4f31199cc9fbcd8d4161e03bb7e9368c24eced3c959
SHA1 hash: f342f7b0b49526047ef80e8fa916ea4c7afefacd
MD5 hash: 3188d2f01ddf123f02b626c390886f66
humanhash: river-violet-pip-georgia
File name:2.dll
Download: download sample
Signature ZLoader
File size:816'128 bytes
First seen:2020-05-12 16:47:38 UTC
Last seen:2020-07-19 19:31:43 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 001652b58a9526749c2429448fdad35a (1 x ZLoader)
ssdeep 24576:OJjx/uzRjsyqSk+1PgStj/OU7nsMsiPas8nUQ0jbTAoWeI:OOjsyqj+BZk0aeI
Threatray 766 similar samples on MalwareBazaar
TLSH D5058C103389D175E57A0B314C32D5F444AABE19DF32995F72E93F0FAA756808A39B0B
Reporter James_inthe_box
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
3
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Zloader
Status:
Malicious
First seen:
2020-05-12 16:47:05 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
22 of 31 (70.97%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
family:zloader botnet:12/05 botnet trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
https://japanjisho.info/wp-parser.php
https://home.comegico.com.mx/wp-parser.php
https://hormonas.comegico.com.mx/wp-parser.php
https://hopime.com/wp-parser.php
https://gavrelets.ru/wp-parser.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments