MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10cc78e17139d3cc2ec90c88806f85d3a660bf445eda3814650200448df846d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 10cc78e17139d3cc2ec90c88806f85d3a660bf445eda3814650200448df846d7
SHA3-384 hash: a835184a8f73618e9ae9963954ea1d021a8d8a198790bdf0da011074df20636e77263fcdc4b6520ccc562a0f305e8e15
SHA1 hash: 144fb730c2709ed545a739ae047910d7cf02ab3c
MD5 hash: e28373620ef8034c8dd0d41e73e481f1
humanhash: batman-ten-muppet-sink
File name:zug12.bin
Download: download sample
Signature Gozi
File size:281'088 bytes
First seen:2020-07-21 21:13:58 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 26161595a9732d17601e4bdfceb9432b (2 x Gozi)
ssdeep 6144:BZ5BSRk7m4TO4uOeS+xJYAOKL4h/Jd9Yv6JBdeCBI:BZaz4K4usaYR9tFeCBI
Threatray 785 similar samples on MalwareBazaar
TLSH 24549E403A82C4BAD5BE19345938D6A6067DBC200F70DDFBABD85E2B4E391C19631E77
Reporter malware_traffic
Tags:dll Gozi IcedID

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-21 21:15:06 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Blacklisted process makes network request
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments