MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ca3ae0f9b573739e66192f15aade1cf3d409ef133a7b6834ad4e387dea498a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4ca3ae0f9b573739e66192f15aade1cf3d409ef133a7b6834ad4e387dea498a5
SHA3-384 hash: de173aca7853bc6452e61370ee3b78f78c014be6a2c0695d420f6eab0d89f2c80d42989fa0726b6d61c3d2eb8d8a7425
SHA1 hash: ec5338822efc141c24c54a6718fb73cfe166a61d
MD5 hash: 500854618bda05096da0a2d244de4e43
humanhash: mirror-eleven-princess-rugby
File name:opywybz.dll
Download: download sample
Signature Gozi
File size:342'528 bytes
First seen:2020-03-29 19:36:25 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash c551e49037ee8b28e8478c51adad077a (1 x Gozi)
ssdeep 6144:ISKto2lJSFk0tq9qRQONo9g6B2qZnNtqx5:7sn3SW0c9qQGCVFZno5
Threatray 43 similar samples on MalwareBazaar
TLSH 5674CF12BF65C473E4296E798813DAF88139BC149F35CEDBB2C43E1FE970651C821A5A
Reporter Racco42
Tags:dll Gozi ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Gozi

DLL dll 4ca3ae0f9b573739e66192f15aade1cf3d409ef133a7b6834ad4e387dea498a5

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::GetWindowsDirectoryA

Comments