🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0d7149c6124a3bade2a501bff03dfd4f217eac94e874f235c7a9984b2b96e26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: d0d7149c6124a3bade2a501bff03dfd4f217eac94e874f235c7a9984b2b96e26
SHA3-384 hash: a94bfbfcfc133c208b9dbde78a4b6aadc565a7049625c14088aa2858611bcb885b70c7e2d4c6f1dc15ef582c6184f028
SHA1 hash: 05e7c0bd618b04a609df133a29a2d4b41a6b7374
MD5 hash: fa01782a11486c3dfaad36e930d2b9f6
humanhash: stairway-fix-india-leopard
File name:cXQT5g
Download: download sample
Signature ZLoader
File size:402'432 bytes
First seen:2020-10-18 05:47:31 UTC
Last seen:2020-10-18 06:35:05 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 0cf9ce4aca71ae41191d14138ced2d69 (3 x ZLoader)
ssdeep 12288:yhMO6cMygxQGkGr/MzzwnCAavul0dA91nNzAUiN:yhPlNGQerEz0nXavs7nNi
TLSH 0A84DF60BA41E026D15E0A3ADC69DAFC252A7D4C8F745CD733C86F1FAA774824734E26
Reporter abuse_ch
Tags:CAN dll geo october14 ZLoader


Avatar
abuse_ch
Botnet ID: october14

ZLoader C2s:
http://kentyckyderby201000.com/web/post.php
http://deemberkentyucky101.com/web/post.php
http://decemberkentuck102981.com/web/post.php
http://wingtonwelbemdon.com/web/post.php
http://donburitimesofindia.com/web/post.php
http://celtictimesofkarishan.com/web/post.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
163
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Creating a file in the %temp% directory
Deleting a recently created file
Replacing files
Delayed writing of the file
Delayed reading of the file
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 299729 Sample: cXQT5g Startdate: 18/10/2020 Architecture: WINDOWS Score: 52 12 Multi AV Scanner detection for submitted file 2->12 14 Machine Learning detection for sample 2->14 6 loaddll32.exe 1 2->6         started        process3 process4 8 rundll32.exe 501 6->8         started        10 rundll32.exe 501 6->10         started       
Threat name:
Win32.Trojan.ZLoader
Status:
Malicious
First seen:
2020-10-17 18:07:00 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
d0d7149c6124a3bade2a501bff03dfd4f217eac94e874f235c7a9984b2b96e26
MD5 hash:
fa01782a11486c3dfaad36e930d2b9f6
SHA1 hash:
05e7c0bd618b04a609df133a29a2d4b41a6b7374
SH256 hash:
c95afcbcabc9e0ab36b88b411a67ec34b6c0695f86336887cdc2f32122bcf930
MD5 hash:
e3823cec680d13ec0f7bdea23eb82301
SHA1 hash:
a40476d4cf81316ea75c0bfa13dc1973f0262d1c
Detections:
win_zloader_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_zloader_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ZLoader

DLL dll d0d7149c6124a3bade2a501bff03dfd4f217eac94e874f235c7a9984b2b96e26

(this sample)

Comments