MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ZLoader
Vendor detections: 8
| SHA256 hash: | f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09 |
|---|---|
| SHA3-384 hash: | d189f4c33175cbdf7224d527afa9fa0c67fb13898a2dcebe91a06fadd713dd6e583a11b6f0df2bb1341adbbf5761607c |
| SHA1 hash: | 3deeff224b359ca2b28a841a116b84b783206adc |
| MD5 hash: | 1d700b208c65ca26efe5fa4be4749569 |
| humanhash: | network-hawaii-gee-comet |
| File name: | favicon.dll |
| Download: | download sample |
| Signature | ZLoader |
| File size: | 662'016 bytes |
| First seen: | 2021-07-07 20:12:59 UTC |
| Last seen: | 2021-07-07 20:49:46 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 5f2bb841560675d1d7ae86cf967cd2bc (1 x ZLoader) |
| ssdeep | 12288:A1Xiy+UrnWHWzB2nWSgg6Uyan4jN3PMLYHBlIfNGwOF4IurIU+ls:JlUKQgWfg6qkHMOF8IU |
| Threatray | 2 similar samples on MalwareBazaar |
| TLSH | T158E48C103399F821D2E663328F61E5E44B4938241B7515CF3AE83BAF1F6D5F3AA25316 |
| Reporter | |
| Tags: | dll ZLoader |
Intelligence
File Origin
# of uploads :
2
# of downloads :
200
Origin country :
n/a
Vendor Threat Intelligence
Detection:
Zloader
Detection(s):
Verdict:
Unknown
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Detection:
zloader
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
zloader
gozi
Result
Malware family:
zloader
Score:
10/10
Tags:
family:zloader botnet:mk1 campaign:mac2 botnet trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Suspicious use of NtCreateUserProcessOtherParentProcess
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
https://dssdffsdf.drld/mm.php
Unpacked files
SH256 hash:
66896fb47870776a23c729bbe34c7e9befc796cddd6774a69df73db413e4cd6b
MD5 hash:
62ca7a28bcbb4ffb10a1ea9a1505ecaa
SHA1 hash:
3dc0d144285cf9f3aff41d2ca3cfb83cee777887
Detections:
win_zloader_auto
SH256 hash:
f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09
MD5 hash:
1d700b208c65ca26efe5fa4be4749569
SHA1 hash:
3deeff224b359ca2b28a841a116b84b783206adc
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.