🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a50844184119e66e5d3a663be6d2d57d72a6748b6ce2d11974c688c8bc40d710. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: a50844184119e66e5d3a663be6d2d57d72a6748b6ce2d11974c688c8bc40d710
SHA3-384 hash: 9db723c5a0cb52d61c08bd43f0367658952b63a79e5016c1891603659a012a2001cdfc3d4e4987009a55131423630b3a
SHA1 hash: 7e572733b2ef7266dfdb237c32d73919df6ae298
MD5 hash: bd91abd60357f47d4a163df3fc27b795
humanhash: carolina-oranges-july-sixteen
File name:bd91abd60357f47d4a163df3fc27b795.exe
Download: download sample
Signature ZLoader
File size:298'496 bytes
First seen:2020-11-01 18:44:37 UTC
Last seen:2020-11-01 20:50:29 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 22c87ff9d53c8eae0251c1eaef3e8242 (3 x ZLoader, 2 x RedLineStealer)
ssdeep 3072:3uVVEh1BJOV5Nl/QTykl92VjEGKIct1gP6vY1vgrypQ3K3GtwvQWMXdiqjjjjjjn:l1BQ1seYGit1gD1vY/A6wvQWCx
TLSH 2954CF1176E5C472D05744321924E2B06636BC326D7489477BE8EF2B2E329D1EBBA34E
Reporter abuse_ch
Tags:exe ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
155
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Deleting a recently created file
Replacing files
Delayed writing of the file
Delayed reading of the file
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
68 / 100
Signature
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Malrep
Status:
Malicious
First seen:
2020-11-01 18:46:06 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
a50844184119e66e5d3a663be6d2d57d72a6748b6ce2d11974c688c8bc40d710
MD5 hash:
bd91abd60357f47d4a163df3fc27b795
SHA1 hash:
7e572733b2ef7266dfdb237c32d73919df6ae298
SH256 hash:
622edbfe71125fd279d60e857354945f78116be75daffb8c4e04f6f8e4dcb94c
MD5 hash:
beb17f2421b6e651ddf9c2af73a8b732
SHA1 hash:
d5b0b8ace9020a219a51fde274d3c2d800e0b024
Detections:
win_zloader_a0 win_zloader_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ZLoader

Executable exe a50844184119e66e5d3a663be6d2d57d72a6748b6ce2d11974c688c8bc40d710

(this sample)

  
Delivery method
Distributed via web download

Comments