🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d74e9aa01bffcb4944742f93ad5b87d4c057f4faad008f04f7397634fe3f234d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d74e9aa01bffcb4944742f93ad5b87d4c057f4faad008f04f7397634fe3f234d
SHA3-384 hash: edcdca27435ab01a248dcb76b8088572435f5e8f07429f9ed4ca1c56a38ce5def33f6e07caf2f37462e750e821104325
SHA1 hash: e060125845cc1c4098f87632f453969ad9ec01ab
MD5 hash: 417457ac3e000697959127259c73ee46
humanhash: sierra-cold-salami-cat
File name:6a9e7107c97762eb1196a64baeadb291
Download: download sample
Signature ZLoader
File size:214'528 bytes
First seen:2020-11-17 12:03:04 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d85aae93bf5cde2e2f2e4b614a57d29e (4 x RaccoonStealer, 1 x ZLoader)
ssdeep 3072:tnwDl1lJiIPMUMEhTo6pWmuRdIDAP2Oh0oF14tO/m92B96W5ryx0d:y1DUUMETotmubnP2O314am92
TLSH 2924D02170E0C031D1EB167B84B4C7B49EBB7C663676298F6F95B5B80F316E2C62530A
Reporter seifreed
Tags:ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Delayed writing of the file
Delayed reading of the file
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 12:06:26 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
family:zloader botnet:canadaloads campaign:nerino botnet trojan
Behaviour
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
https://monanuslanus.com/bFnF0y1r/7QKpXmV3Pz.php
https://lericastrongs.com/bFnF0y1r/7QKpXmV3Pz.php
https://hyllionsudks.com/bFnF0y1r/7QKpXmV3Pz.php
https://crimewasddef.com/bFnF0y1r/7QKpXmV3Pz.php
https://derekdsingel.com/bFnF0y1r/7QKpXmV3Pz.php
https://simplereffiret.com/bFnF0y1r/7QKpXmV3Pz.php
https://regeerscomba.com/bFnF0y1r/7QKpXmV3Pz.php
Unpacked files
SH256 hash:
d74e9aa01bffcb4944742f93ad5b87d4c057f4faad008f04f7397634fe3f234d
MD5 hash:
417457ac3e000697959127259c73ee46
SHA1 hash:
e060125845cc1c4098f87632f453969ad9ec01ab
SH256 hash:
89137498ff2c88180080ee2f3772ee0a24812857493da798665679f22a30bcdf
MD5 hash:
1c0d0b80f2c17158e62bb374dfef9747
SHA1 hash:
68f10ab373b4dacb3e76d3dd3da830a17edc0c72
Detections:
win_zloader_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments