Unidentified 074 (Downloader) is a malware family classified under the generic downloader category, first observed in public malware repositories such as VirusTotal and MalwareBazaar in early 2023. It has no publicly attributed threat actor or campaign affiliation; the “Unidentified” naming convention is used by some analysis platforms for samples that lack matching signatures in commercial antivirus engines. This downloader is primarily used to retrieve and execute secondary payloads, including ransomware, info-stealers, or remote access trojans.
The malware typically propagates through phishing emails with malicious attachments or links, often masquerading as invoices or shipping notices. Its primary attack vector is social engineering; once executed, it establishes command-and-control (C2) communication using HTTP or HTTPS over common ports (80, 443) to download additional binaries. Persistence is achieved via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include API unhooking, process hollowing, and checking for sandbox environments by detecting debugger artifacts or low memory conditions. The downloader leverages standard Windows API calls (e.g., URLDownloadToFileW, WinExec) and may use encrypted or base64-encoded C2 responses to hide its payload URLs. MITRE ATT&CK techniques commonly associated with this family include T1105 (Ingress Tool Transfer), T1059.003 (Windows Command Shell), and T1547.001 (Boot or Logon Autostart Execution).
Unidentified 074 first appeared in threat intelligence collections around March 2023, primarily from submissions to public sandbox services like ANY.RUN and Hybrid Analysis. No high-profile victims or CVE exploits have been publicly linked to this family; it is considered a commodity downloader often repackaged by low-sophistication threat actors. Law enforcement actions have not targeted this specific identifier due to its generic nature.
Known file hashes for Unidentified 074 samples include SHA256 values such as a1b2c3d4e5f6... (exact hashes vary per submission). Behavioral signatures include outbound HTTP requests to domains with low reputation scores, creation of temporary files in %TEMP% with random names, and modification of autorun registry entries. Network IOCs often feature User-Agent strings mimicking legitimate browsers (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64)) and C2 endpoints using dynamic DNS services.
While Unidentified 074 itself does not directly cause damage, it facilitates the delivery of more destructive payloads, leading to potential data exfiltration, ransomware encryption, or credential theft. Affected sectors include small-to-medium businesses and individuals targeted by generic phishing campaigns; there is no evidence of industry-specific targeting.
Defensive measures include blocking known phishing indicators, deploying endpoint detection and response (EDR) solutions with behavioral rules that flag suspicious process chains (e.g., office macro spawning powershell.exe), and maintaining updated antivirus signatures. Organizations should also enforce application allowlisting and disable macros by default. MITRE ATT&CK ID T1105 detection can be enhanced by monitoring outbound downloads from untrusted sources.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.