MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a47685b867e6b164a812a05f35b6732c9b81f1fc75b2a7242c18436a9329d247. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a47685b867e6b164a812a05f35b6732c9b81f1fc75b2a7242c18436a9329d247
SHA3-384 hash: 05ba4deaad6040c18096d6631bdc9be629932b6e5041f026d5bde7d1ce1a4abbf308186e05b1c104bd543bb892cbfbf9
SHA1 hash: 84ef96d8c3257db85d7358d50ccbfa3ca5d70828
MD5 hash: d2d259229212aed1a346b8e0187b7d92
humanhash: robin-network-georgia-delta
File name:RO7jY.html
Download: download sample
Signature Gozi
File size:466'944 bytes
First seen:2020-04-14 17:57:03 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash fb0033b6d69da51dbda372f7c7a99ba6 (1 x Gozi)
ssdeep 12288:PCJB0qZTQvJtLTQIGKjACUOAjBwqB6qGqi:PHA0JlQIZj1UO8iq8Hqi
Threatray 55 similar samples on MalwareBazaar
TLSH 1AA4AE413A97C074D11A01F08F75D96825B8BEB45FA50DEBB3E4AEAB71B22D0533DB12
Reporter abuse_ch
Tags:dll Gozi ZLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

DLL dll a47685b867e6b164a812a05f35b6732c9b81f1fc75b2a7242c18436a9329d247

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW

Comments