MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4f3e1c36ef734927967d40bba87fc620abe5c5049b0e67fd3cc3dab9c763c7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information Yara Comments

SHA256 hash: c4f3e1c36ef734927967d40bba87fc620abe5c5049b0e67fd3cc3dab9c763c7a
SHA3-384 hash: 491483cb43ec3d279eac08807d4dc2f762ba0d7bbb4bcd7e94a046d7a041fcf296b4730145f225f9cfe2dda2fe3f958c
SHA1 hash: 34f02fba4e619d718b69bec2152a75683fa6a3c8
MD5 hash: 3718fe99f772c81aa908369cd7279eac
humanhash: colorado-illinois-table-charlie
File name:zloader 2_1.1.21.0.vir
Download: download sample
Signature ZLoader
File size:174'592 bytes
First seen:2020-07-19 17:14:52 UTC
Last seen:2020-07-19 19:13:26 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash c4a8909c0bccc13eaa9bdf93bacea9e6
ssdeep 3072:REOpmT46vL0hxtHlGAJyezW+iVu8FsVWswU5rp4h:RiTvvAhfAAJrriVdsVWGI
TLSH 240405055850C630ED0500719ACEF77E8C2EC52D2B22AAEBCBD1C8D05BD86F579BE26D
Reporter @tildedennis
Tags:ZLoader zloader 2


Twitter
@tildedennis
zloader 2 version 1.1.21.0

Intelligence


File Origin
# of uploads :
2
# of downloads :
16
Origin country :
US US
Mail intelligence
No data
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Creating a window
Unauthorized injection to a recently created process
Connection attempt to an infection source
Result
Threat name:
ZLoader
Detection:
malicious
Classification:
spre.troj
Score:
68 / 100
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Zbot
Status:
Malicious
First seen:
2020-03-20 07:04:00 UTC
AV detection:
22 of 31 (70.97%)
Threat level
  2/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
family:zloader
Behaviour
Zloader family
Malware Config
Extraction:
https://105711.com/docs.php
https://209711.com/process.php
https://106311.com/comegetsome.php
https://124331.com/success.php
Threat name:
Unknown
Score:
1.00

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments