MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc8b29f27771d4f8c16ce6e81b180ca85627b7b6217a7ee5560679317c772ce9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZeuS


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bc8b29f27771d4f8c16ce6e81b180ca85627b7b6217a7ee5560679317c772ce9
SHA3-384 hash: 5dc1eeca362a32c35ea2f8729f08898e2b66b398d9e1a476bb138a64b2078c0b834487764d06d17de89f7bac5157d099
SHA1 hash: f34d166a78959b122d8a1da9edbd5c7c0be5bc92
MD5 hash: 2272725ba8d7a857bb8600423b190eae
humanhash: single-alpha-pizza-summer
File name:bc8b29f27771d4f8c16ce6e81b180ca85627b7b6217a7ee5560679317c772ce9
Download: download sample
Signature ZeuS
File size:85'504 bytes
First seen:2020-08-16 15:23:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 049f442ab1d5a967fbe461eb8a1fffc1 (1 x ZeuS)
ssdeep 1536:lFwaN6Q110kgWHrGK04QvY/T7VmFHlbHKoGoLi8Qx:DNUQJgWLGumYnoGoLi84
Threatray 108 similar samples on MalwareBazaar
TLSH 9283F1BADF04343BDD0F02F17F4245F5C7D922261A2B51778C637D6A6ABDE82CA9005A
Reporter tildedennis
Tags:unnamed 4 ZeuS


Avatar
tildedennis
unnamed 4 version 1.6.2.1

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'717
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
72 / 100
Signature
Contains functionality to detect virtual machines (IN, VMware)
Detected unpacking (changes PE section rights)
Detected unpacking (creates a PE file in dynamic memory)
Detected unpacking (overwrites its own PE header)
Machine Learning detection for sample
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Zeus
Status:
Malicious
First seen:
2011-12-18 01:04:00 UTC
AV detection:
23 of 25 (92.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Runs net.exe
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments