{"id":2895,"date":"2021-05-31T22:08:32","date_gmt":"2021-06-01T03:08:32","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2895"},"modified":"2021-05-31T22:08:33","modified_gmt":"2021-06-01T03:08:33","slug":"zloader-a-dangerous-malware-distributor","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/","title":{"rendered":"ZLoader &#8211; A Dangerous malware Distributor"},"content":{"rendered":"\n<p>ZLoader (also known as DELoader and Terdot) is a malicious program that is distributed through malicious web pages that display a false error notification.In addition, research shows that ZLoader is designed to infect systems with another malicious program, a banking trojan called Zeus.<\/p>\n\n\n\n<p>In one of the ZLoader campaigns, detected on April 4, the victim was informed of the possibility of having been in contact with a family member, friend or neighbor with coronavirus and, through a malicious attachment, they were offered supposedly more details to be able to take a free medical test at your nearest hospital. From Proofpoint they comment that, after almost two years since the last activity of the ZLoader, they began to observe campaigns that used a new banking malware with a functionality and network traffic similar to those of then.<\/p>\n\n\n\n<p>The ZLoader malware first appeared in 2006 as a variant of the Zeus banking Trojan. It uses webinject attacks to steal credentials and other private data of users belonging to the target financial institutions. It can also be done with passwords and cookies stored on the victims&#8217; web browsers. With all this information stolen, the ZLoader could use the Virtual Network Computing (VNC) client to allow cybercriminals to connect to the victim&#8217;s system and thus carry out fraudulent transactions from a legitimate device.<\/p>\n\n\n\n<p>This threat employs various mechanisms to hinder detection and reverse engineering, such as junk code, constant obfuscation, hashing of Windows API functions, string encryption, and command-and-control-based blacklisting. Some of the campaigns analyzed since January by Proofpoint, including more than a hundred, were targeted at users in the United States, Canada, Germany, Poland and Australia.<\/p>\n\n\n\n<p>We can follow some tips to avoid this threat such as: Do not download software through third-party downloaders, peer-to-peer networks or any other tool that we mentioned above. It should be done using only official and trusted websites and direct download links. Attachments (or web links) should not be opened in irrelevant emails that are received from unknown and suspicious addresses.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/\">BazaLoader threat posing as legitimate sites<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/hancitor-is-a-trojan-that-has-evolved\/\">Hancitor is a Trojan that has evolved<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ZLoader (also known as DELoader and Terdot) is a malicious program that is distributed through malicious web pages that display a false error notification.In addition, research shows that ZLoader is designed to infect systems with another malicious program, a banking trojan called Zeus. In one of the ZLoader campaigns, detected on April 4, the victim [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2895","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ZLoader - A Dangerous malware Distributor - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Loaders are threats that do not attack alone, they use other dangerous malware to potentially attack and today we will see one called ZLoader\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ZLoader - A Dangerous malware Distributor - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Loaders are threats that do not attack alone, they use other dangerous malware to potentially attack and today we will see one called ZLoader\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-01T03:08:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-01T03:08:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/ZLoader.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"700\" \/>\n\t<meta property=\"og:image:height\" content=\"480\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"ZLoader &#8211; A Dangerous malware Distributor\",\"datePublished\":\"2021-06-01T03:08:32+00:00\",\"dateModified\":\"2021-06-01T03:08:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/\"},\"wordCount\":355,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/ZLoader.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/\",\"name\":\"ZLoader - A Dangerous malware Distributor - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/ZLoader.jpg\",\"datePublished\":\"2021-06-01T03:08:32+00:00\",\"dateModified\":\"2021-06-01T03:08:33+00:00\",\"description\":\"Loaders are threats that do not attack alone, they use other dangerous malware to potentially attack and today we will see one called ZLoader\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/ZLoader.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/ZLoader.jpg\",\"width\":700,\"height\":480},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zloader-a-dangerous-malware-distributor\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ZLoader &#8211; A Dangerous malware Distributor\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ZLoader - A Dangerous malware Distributor - Truxgo Server Blog","description":"Loaders are threats that do not attack alone, they use other dangerous malware to potentially attack and today we will see one called ZLoader","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/","og_locale":"es_MX","og_type":"article","og_title":"ZLoader - A Dangerous malware Distributor - Truxgo Server Blog","og_description":"Loaders are threats that do not attack alone, they use other dangerous malware to potentially attack and today we will see one called ZLoader","og_url":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-01T03:08:32+00:00","article_modified_time":"2021-06-01T03:08:33+00:00","og_image":[{"width":700,"height":480,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/ZLoader.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"ZLoader &#8211; A Dangerous malware Distributor","datePublished":"2021-06-01T03:08:32+00:00","dateModified":"2021-06-01T03:08:33+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/"},"wordCount":355,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/ZLoader.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/","url":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/","name":"ZLoader - A Dangerous malware Distributor - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/ZLoader.jpg","datePublished":"2021-06-01T03:08:32+00:00","dateModified":"2021-06-01T03:08:33+00:00","description":"Loaders are threats that do not attack alone, they use other dangerous malware to potentially attack and today we will see one called ZLoader","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/ZLoader.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/ZLoader.jpg","width":700,"height":480},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/zloader-a-dangerous-malware-distributor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"ZLoader &#8211; A Dangerous malware Distributor"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2895"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2895\/revisions"}],"predecessor-version":[{"id":2920,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2895\/revisions\/2920"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2896"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}