🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09
SHA3-384 hash: d189f4c33175cbdf7224d527afa9fa0c67fb13898a2dcebe91a06fadd713dd6e583a11b6f0df2bb1341adbbf5761607c
SHA1 hash: 3deeff224b359ca2b28a841a116b84b783206adc
MD5 hash: 1d700b208c65ca26efe5fa4be4749569
humanhash: network-hawaii-gee-comet
File name:favicon.dll
Download: download sample
Signature ZLoader
File size:662'016 bytes
First seen:2021-07-07 20:12:59 UTC
Last seen:2021-07-07 20:49:46 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 5f2bb841560675d1d7ae86cf967cd2bc (1 x ZLoader)
ssdeep 12288:A1Xiy+UrnWHWzB2nWSgg6Uyan4jN3PMLYHBlIfNGwOF4IurIU+ls:JlUKQgWfg6qkHMOF8IU
Threatray 2 similar samples on MalwareBazaar
TLSH T158E48C103399F821D2E663328F61E5E44B4938241B7515CF3AE83BAF1F6D5F3AA25316
Reporter Kostastsale
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
200
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
zloader
Score:
  10/10
Tags:
family:zloader botnet:mk1 campaign:mac2 botnet trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Suspicious use of NtCreateUserProcessOtherParentProcess
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
https://dssdffsdf.drld/mm.php
Unpacked files
SH256 hash:
66896fb47870776a23c729bbe34c7e9befc796cddd6774a69df73db413e4cd6b
MD5 hash:
62ca7a28bcbb4ffb10a1ea9a1505ecaa
SHA1 hash:
3dc0d144285cf9f3aff41d2ca3cfb83cee777887
Detections:
win_zloader_auto
SH256 hash:
f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09
MD5 hash:
1d700b208c65ca26efe5fa4be4749569
SHA1 hash:
3deeff224b359ca2b28a841a116b84b783206adc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ZLoader

DLL dll f97954d9c80dbfee223fb704863c5a156912f450eee2d0510af6301dfd919f09

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments