MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa5758be81ae8ec4d4f2c4f403a9caa31fd6508100d3cd718190ab9320f3eba4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ZLoader


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: fa5758be81ae8ec4d4f2c4f403a9caa31fd6508100d3cd718190ab9320f3eba4
SHA3-384 hash: 1ab9993a7b42abeeb638b54403c3cbd5c089a596de4861db4258dfe0519cadc34913eabf8888f2e7cbded37300bdedaf
SHA1 hash: 935a5c5404833d0fa049dfbdec302bcd87e9a1cc
MD5 hash: 417be31cf5316bc66a340b1d47af187e
humanhash: cup-stream-lemon-quebec
File name:fa5758be81ae8ec4d4f2c4f403a9caa31fd6508100d3cd718190ab9320f3eba4.dll
Download: download sample
Signature ZLoader
File size:585'728 bytes
First seen:2020-10-20 15:32:22 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 12370bc90c1f7942c66469afbdb625f9 (2 x ZLoader)
ssdeep 12288:cPAHM4Qd+m3CDMpLVd53TpEPyBU5RHwOgQLg8fHHRI2TF1:qYjQ73CDMpHTp1U5RHwOfxH7Tz
Threatray 37 similar samples on MalwareBazaar
TLSH 99C4E0133686D53AC66AC239CD85EDFC96957D09EEA46C4330C53F4F3A32A518B39B06
Reporter Secu0133
Tags:dll ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Creating a file in the %temp% directory
Delayed writing of the file
Delayed reading of the file
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
(
)
.
a
b
c
D
e
f
g
h
I
k
l
m
n
o
r
S
t
u
w
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 301218 Sample: 7wXLmylRKg.dll Startdate: 20/10/2020 Architecture: WINDOWS Score: 48 14 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->14 6 loaddll32.exe 1 2->6         started        8 msiexec.exe 2->8         started        process3 process4 10 rundll32.exe 6->10         started        12 rundll32.exe 1 6->12         started       
Threat name:
Win32.Trojan.ZLoader
Status:
Malicious
First seen:
2020-10-20 15:34:05 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
zloader
Score:
  10/10
Tags:
trojan botnet family:zloader
Behaviour
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetThreadContext
Blacklisted process makes network request
Suspicious use of NtCreateUserProcessOtherParentProcess
Zloader, Terdot, DELoader, ZeusSphinx
Malware Config
C2 Extraction:
http://kentyckyderby201000.com/web/post.php
http://deemberkentyucky101.com/web/post.php
http://decemberkentuck102981.com/web/post.php
http://wingtonwelbemdon.com/web/post.php
http://donburitimesofindia.com/web/post.php
http://celtictimesofkarishan.com/web/post.php
Unpacked files
SH256 hash:
7f8ba3d850bc3f0ab491ec1d46507e3c0d887a7a574b7166a8ad356352bf0663
MD5 hash:
0cc62ffc8a4788af16d7ba58b442f8f1
SHA1 hash:
f82bf00efcc0bb1cdc43ac91c0c496d70a263bf1
Detections:
win_zloader_auto
SH256 hash:
fa5758be81ae8ec4d4f2c4f403a9caa31fd6508100d3cd718190ab9320f3eba4
MD5 hash:
417be31cf5316bc66a340b1d47af187e
SHA1 hash:
935a5c5404833d0fa049dfbdec302bcd87e9a1cc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments