MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1c6632f98426b86189fde78f0f529fe42eeb2653412b0003090ae6a42c91d268. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 11
| SHA256 hash: | 1c6632f98426b86189fde78f0f529fe42eeb2653412b0003090ae6a42c91d268 |
|---|---|
| SHA3-384 hash: | e8789c47099afdb9a691741a2b85b45a8df54f3e49dbac0cfe3f632fc21ef45a528166a1fcda1fb205040674ceeeff73 |
| SHA1 hash: | ddd5e59c4a302a6d05a8bc063eada8fd518b97cb |
| MD5 hash: | 61f7acd0651b59206e447fc63c46b855 |
| humanhash: | skylark-edward-tango-fish |
| File name: | notepad |
| Download: | download sample |
| Signature | Gozi |
| File size: | 281'088 bytes |
| First seen: | 2022-03-08 10:35:51 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | fab832f0eb05efca0f6cd66bd4fb20fa (2 x Gozi, 2 x Stop, 1 x Loki) |
| ssdeep | 3072:xezygtkNJkL8+zFi+BfD1t0e7yJIl65kEVggjcGkNIVqII4Y:YHtkrkL8+cgD1t0xJIlPg7ITsqF4 |
| Threatray | 6'049 similar samples on MalwareBazaar |
| TLSH | T14354AED236A0FC3AC49235716835C7E15A3E7831EAB4980777740B2E2E70BD1BA76346 |
| File icon (PE): | |
| dhash icon | 367e7c7f767e6e72 (2 x RedLineStealer, 2 x Smoke Loader, 1 x Loki) |
| Reporter | |
| Tags: | exe Gozi isfb mise Ursnif |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
linkspremium.ru
premiumlists.ru
Unpacked files
9eb0bdb45d505a24290b3fe9adb1ac5c856238e91358fcf7e6af73d9a1b9c244
da620c65032d49a148b428dab566fed2a1a9af6fb0f53ffc4ea75ae54a2cd6a9
1c6632f98426b86189fde78f0f529fe42eeb2653412b0003090ae6a42c91d268
4bd004047533752383486ead4f6ce67459d38f816d63d110744f0df009b2d022
57d9f65f62b63e02b194c97d66d478f70a75df94abc134d45e02539cbb33d961
14e041ad11be886018e643ed1cff9abe512e787bec794ab585e75f91e2da119e
02f23031b04660ce5d0a3dbd6862640895e37c649963c02d0b367a17d8422ffe
bc2bd3c448b2348629da59a454f409ad5b60f2eb21f175e7e49dd04b2703c0ea
f1d890163f681d1c94337e6459b9c233180ebe755e94095315f7acf0171e1eea
eda3487d5cce3777e504ae88f362c2352de1642fa86200e005ba5a7a3bfbdec0
50ed0329ffb7ae83f7a8042ef7f6bd5af5f308e52f479965358cfe4d646b1847
9eb0bdb45d505a24290b3fe9adb1ac5c856238e91358fcf7e6af73d9a1b9c244
da620c65032d49a148b428dab566fed2a1a9af6fb0f53ffc4ea75ae54a2cd6a9
1c6632f98426b86189fde78f0f529fe42eeb2653412b0003090ae6a42c91d268
4bd004047533752383486ead4f6ce67459d38f816d63d110744f0df009b2d022
57d9f65f62b63e02b194c97d66d478f70a75df94abc134d45e02539cbb33d961
14e041ad11be886018e643ed1cff9abe512e787bec794ab585e75f91e2da119e
02f23031b04660ce5d0a3dbd6862640895e37c649963c02d0b367a17d8422ffe
bc2bd3c448b2348629da59a454f409ad5b60f2eb21f175e7e49dd04b2703c0ea
f1d890163f681d1c94337e6459b9c233180ebe755e94095315f7acf0171e1eea
eda3487d5cce3777e504ae88f362c2352de1642fa86200e005ba5a7a3bfbdec0
50ed0329ffb7ae83f7a8042ef7f6bd5af5f308e52f479965358cfe4d646b1847
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | win_isfb_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.isfb. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.