MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c421ff35f676e2a886e33879a324da5660a9d94dd77edc1791f431c124402a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 8c421ff35f676e2a886e33879a324da5660a9d94dd77edc1791f431c124402a4
SHA3-384 hash: da2d54c10a2abc7f653a63fafcc3ba43b69ae4b639c4ea47a2397ece5b68b7c61f0c0f4226a333b8108cac6570bcb804
SHA1 hash: 1e39cb986dabe319dd57e5fe8ab240374e9f9d66
MD5 hash: 5c6a63347772e521f7730a6ffd550317
humanhash: hot-batman-twenty-sixteen
File name:5c6a63347772e521f7730a6ffd550317.exe
Download: download sample
Signature Gozi
File size:174'080 bytes
First seen:2020-10-09 09:01:55 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 40e1b4bb494badf2883ac091478da7b3 (1 x Gozi)
ssdeep 3072:NOYkVd/f2n8tl52R/ACY0XOQixSbhrnG7HT+PIm1eokxC9:NOY+XWIPiACY06yhrWT+PvAi
Threatray 46 similar samples on MalwareBazaar
TLSH BF046F07FA48256AF09ED73D34772A9A6FC2D23374E1E9D901B696070B9F242D70742B
Reporter abuse_ch
Tags:exe Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
225
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Using the Windows Management Instrumentation requests
Launching a process
Creating a window
DNS request
Sending an HTTP GET request
Searching for the window
Deleting a recently created file
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
20 / 100
Signature
a
c
d
e
f
g
h
i
L
M
n
o
p
r
s
t
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2020-10-09 09:03:05 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
banker trojan family:gozi_ifsb
Behaviour
Suspicious use of WriteProcessMemory
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Blacklisted process makes network request
Gozi, Gozi IFSB
Unpacked files
SH256 hash:
8c421ff35f676e2a886e33879a324da5660a9d94dd77edc1791f431c124402a4
MD5 hash:
5c6a63347772e521f7730a6ffd550317
SHA1 hash:
1e39cb986dabe319dd57e5fe8ab240374e9f9d66
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

Executable exe 8c421ff35f676e2a886e33879a324da5660a9d94dd77edc1791f431c124402a4

(this sample)

Comments