🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d25dfd45ca90031708daea80e549c053c7b27990be1d7b791994d60f2bb4d187. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d25dfd45ca90031708daea80e549c053c7b27990be1d7b791994d60f2bb4d187
SHA3-384 hash: 4ef40d242a0b027f677baf754ca14f352bf8d6894ee3361c854cd25ad0621f8aa5b31d39b483f4926e619f4213b9db79
SHA1 hash: c09b9974129a0c37ae64e12b1fd41afb92fdbe47
MD5 hash: 5210348e7cc6814dc4e73e685e16c492
humanhash: lima-may-eleven-nitrogen
File name:R-2003.xls
Download: download sample
Signature ZLoader
File size:152'576 bytes
First seen:2020-09-21 18:40:07 UTC
Last seen:Never
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 3072:yk3hOdsylKlgxopeiBNhZFGzE+cL2kdAXoAL6hvAXNdL4HHO+tpyu:yk3hOdsylKlgxopeiBNhZF+E+W2kdAjg
TLSH 6FE30E56C989ABB6C3D0C2346F4F56C01647F975304A8FF3EAD532B4BB2B67016582B2
Reporter theDark3d
Tags:excel hiddenmacro Loader ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% directory
Creating a process with a hidden window
Deleting a recently created file
Possible injection to a system process
Launching a process by exploiting the app vulnerability
Creating a process from a recently created file
Result
Threat name:
Hidden Macro 4.0
Detection:
malicious
Classification:
expl.evad.spre
Score:
100 / 100
Signature
Document exploit detected (creates forbidden files)
Document exploit detected (process start blacklist hit)
Found Excel 4.0 Macro with suspicious formulas
Injects code into the Windows Explorer (explorer.exe)
Microsoft Office drops suspicious files
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
Sigma detected: Office product drops script at suspicious location
System process connects to network (likely due to code injection or exploit)
Yara detected VBS Launcher Generic
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 288272 Sample: R-2003.xls Startdate: 21/09/2020 Architecture: WINDOWS Score: 100 47 Multi AV Scanner detection for submitted file 2->47 49 Sigma detected: Office product drops script at suspicious location 2->49 51 Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros) 2->51 53 4 other signatures 2->53 6 EXCEL.EXE 29 40 2->6         started        10 explorer.exe 2->10         started        12 explorer.exe 2->12         started        14 explorer.exe 5 2->14         started        process3 file4 31 C:\Users\user\AppData\...\R-2003.xls.LNK, MS 6->31 dropped 33 C:\Users\user\AppData\Local\Temp\paSa.vbs, ASCII 6->33 dropped 35 C:\Users\user\AppData\Local\Temp\eBbSA.vbs, ASCII 6->35 dropped 37 C:\Users\user\AppData\Local\...\AU01Hvh.vbs, ASCII 6->37 dropped 55 Document exploit detected (creates forbidden files) 6->55 57 Injects code into the Windows Explorer (explorer.exe) 6->57 59 Document exploit detected (process start blacklist hit) 6->59 61 Microsoft Office drops suspicious files 6->61 16 explorer.exe 1 6->16         started        19 explorer.exe 1 6->19         started        21 explorer.exe 1 6->21         started        23 wscript.exe 1 10->23         started        27 wscript.exe 12->27         started        29 wscript.exe 1 14->29         started        signatures5 process6 dnsIp7 41 192.168.2.1 unknown unknown 16->41 43 cirabelcr6dito.com 185.98.131.155, 443, 49737 RMI-FITECHFR France 23->43 45 chuguadventures.co.tz 192.81.249.5, 443, 49736 AS40676US United States 23->45 39 C:\Users\user\AppData\Local\Temp\YOUB.html, HTML 23->39 dropped 63 System process connects to network (likely due to code injection or exploit) 23->63 file8 signatures9
Threat name:
Document-Word.Trojan.ZLoader
Status:
Suspicious
First seen:
2020-09-21 18:42:06 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Suspicious Office macro
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments