MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d74e9aa01bffcb4944742f93ad5b87d4c057f4faad008f04f7397634fe3f234d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ZLoader
Vendor detections: 4
| SHA256 hash: | d74e9aa01bffcb4944742f93ad5b87d4c057f4faad008f04f7397634fe3f234d |
|---|---|
| SHA3-384 hash: | edcdca27435ab01a248dcb76b8088572435f5e8f07429f9ed4ca1c56a38ce5def33f6e07caf2f37462e750e821104325 |
| SHA1 hash: | e060125845cc1c4098f87632f453969ad9ec01ab |
| MD5 hash: | 417457ac3e000697959127259c73ee46 |
| humanhash: | sierra-cold-salami-cat |
| File name: | 6a9e7107c97762eb1196a64baeadb291 |
| Download: | download sample |
| Signature | ZLoader |
| File size: | 214'528 bytes |
| First seen: | 2020-11-17 12:03:04 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | d85aae93bf5cde2e2f2e4b614a57d29e (4 x RaccoonStealer, 1 x ZLoader) |
| ssdeep | 3072:tnwDl1lJiIPMUMEhTo6pWmuRdIDAP2Oh0oF14tO/m92B96W5ryx0d:y1DUUMETotmubnP2O314am92 |
| TLSH | 2924D02170E0C031D1EB167B84B4C7B49EBB7C663676298F6F95B5B80F316E2C62530A |
| Reporter | |
| Tags: | ZLoader |
Intelligence
File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Behaviour
Creating a file in the %temp% directory
Delayed writing of the file
Delayed reading of the file
Threat name:
Win32.Trojan.Glupteba
Status:
Malicious
First seen:
2020-11-17 12:06:26 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
5/5
Result
Malware family:
zloader
Score:
10/10
Tags:
family:zloader botnet:canadaloads campaign:nerino botnet trojan
Behaviour
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
https://monanuslanus.com/bFnF0y1r/7QKpXmV3Pz.php
https://lericastrongs.com/bFnF0y1r/7QKpXmV3Pz.php
https://hyllionsudks.com/bFnF0y1r/7QKpXmV3Pz.php
https://crimewasddef.com/bFnF0y1r/7QKpXmV3Pz.php
https://derekdsingel.com/bFnF0y1r/7QKpXmV3Pz.php
https://simplereffiret.com/bFnF0y1r/7QKpXmV3Pz.php
https://regeerscomba.com/bFnF0y1r/7QKpXmV3Pz.php
https://lericastrongs.com/bFnF0y1r/7QKpXmV3Pz.php
https://hyllionsudks.com/bFnF0y1r/7QKpXmV3Pz.php
https://crimewasddef.com/bFnF0y1r/7QKpXmV3Pz.php
https://derekdsingel.com/bFnF0y1r/7QKpXmV3Pz.php
https://simplereffiret.com/bFnF0y1r/7QKpXmV3Pz.php
https://regeerscomba.com/bFnF0y1r/7QKpXmV3Pz.php
Unpacked files
SH256 hash:
d74e9aa01bffcb4944742f93ad5b87d4c057f4faad008f04f7397634fe3f234d
MD5 hash:
417457ac3e000697959127259c73ee46
SHA1 hash:
e060125845cc1c4098f87632f453969ad9ec01ab
SH256 hash:
89137498ff2c88180080ee2f3772ee0a24812857493da798665679f22a30bcdf
MD5 hash:
1c0d0b80f2c17158e62bb374dfef9747
SHA1 hash:
68f10ab373b4dacb3e76d3dd3da830a17edc0c72
Detections:
win_zloader_auto
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Delivery method
Other
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.