MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb398cef8fc5e3140ceaa0d7f52911f2011eee2283541b0d67e659f3dc8277eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information Yara Comments

SHA256 hash: fb398cef8fc5e3140ceaa0d7f52911f2011eee2283541b0d67e659f3dc8277eb
SHA3-384 hash: e03cf23c3c181cc416e7f2a71b48512775389c67b457f4243dd26cdfefc4f5eaf8124df03676e1b3cb075d4110e13cd3
SHA1 hash: 394135154ee783853fde07de29ee86d661f0a854
MD5 hash: b76d1665c118ec33404b1e5dc064ccbc
humanhash: burger-pennsylvania-batman-utah
File name:zeus 1_1.2.1.0.vir
Download: download sample
Signature ZeuS
File size:86'016 bytes
First seen:2020-07-19 19:34:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1f739472341b7e2a3b11f15187463d9d
ssdeep 1536:goErE801yLzJY6ZbztjgbSFUH/wA9xFk3edhGDkheIB:lqE80AVY6N97I4A9cedhGWe
TLSH 8C83F10F6D74C9E6D09B26B47EA8167A2614994715822292AF031CDFF1F8F2E7C39DC1
Reporter @tildedennis
Tags:ZeuS zeus 1


Twitter
@tildedennis
zeus 1 version 1.2.1.0

Intelligence


File Origin
# of uploads :
1
# of downloads :
20
Origin country :
FR FR
Mail intelligence
No data
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Unauthorized injection to a recently created process
Connection attempt to an infection source
Threat name:
Win32.Trojan.Zbot
Status:
Malicious
First seen:
2011-06-20 02:40:00 UTC
AV detection:
42 of 45 (93.33%)
Threat level
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Program crash
Threat name:
Unknown
Score:
1.00

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments