MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5ecdc843c22bf650e78bd9b4a533adabc49d0bfb8b183e9f1023862f1600ea8e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 3
| SHA256 hash: | 5ecdc843c22bf650e78bd9b4a533adabc49d0bfb8b183e9f1023862f1600ea8e |
|---|---|
| SHA3-384 hash: | 181c9528a5fe90bb46b936322b7c328268c3faa49862ab4e970dedd5e4e8e615f3cd1fd560488e18b571ef627dc0e4ee |
| SHA1 hash: | 7745ccc1306f4cee4de3a4dfe3ce3b1fa1181c9c |
| MD5 hash: | 95ec64753e0f947e8b11a23a5ca14be0 |
| humanhash: | grey-monkey-nine-uranus |
| File name: | vjd7f2js.dll |
| Download: | download sample |
| Signature | Gozi |
| File size: | 282'624 bytes |
| First seen: | 2020-03-25 15:55:50 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | bed6e84cb09574d634dbd34585ef56e7 (2 x Gozi) |
| ssdeep | 6144:tx+EETSpK7g5GPrT/kh6DWBbBCrIMuAWaULcka:trIgW8IWNBCTuNyk |
| Threatray | 50 similar samples on MalwareBazaar |
| TLSH | 2F544A6ABE4480A1D41D2DBC8426E9F88C6DEC04FE26916F76F4FE7F14742C46425AE3 |
| Reporter | |
| Tags: | dll Gozi ZLoader |
abuse_ch
Unknown payload (ZLoader? Ostap? Dridex?) distributed via malspam -> xlsx -> payload URL:https://gfhudnjv.xyz/vjd7f2js
Various subjects, sending IPs and email addresses
Intelligence
File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-03-26 02:37:37 UTC
File Type:
PE (Dll)
AV detection:
23 of 31 (74.19%)
Threat level:
5/5
Verdict:
malicious
Label(s):
gozi
Similar samples:
+ 40 additional samples on MalwareBazaar
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
54526d97a35da502ca952d735d326e3efdc5b425bd56722eb1ef5aa835db1397
Dropped by
MD5 0c2be50b400dc046a8b34e4ec68f94d0
Dropped by
SHA256 54526d97a35da502ca952d735d326e3efdc5b425bd56722eb1ef5aa835db1397
Delivery method
Distributed via web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::LoadLibraryA KERNEL32.dll::GetStartupInfoA KERNEL32.dll::GetCommandLineA |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::GetSystemDirectoryA |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.ZLoader C&Cs:
https://wgyvjbse.pw/milagrecf.php
https://botiq.xyz/milagrecf.php