🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2016f2e0e206823eab06ef55dd36d15e882fb4b7d241c2148617781a36c20e84. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2016f2e0e206823eab06ef55dd36d15e882fb4b7d241c2148617781a36c20e84
SHA3-384 hash: d95e019dec291215d60b5c37b014ab7c046727177c022417f99d78c4d405f67381f45722c532b1133aad1819d76683c1
SHA1 hash: 1c81cbc28336fa62d04c43fac193e8ed09a9bef8
MD5 hash: 46e8064942475e4edcd7af3ec42ca9ef
humanhash: london-kitten-triple-mississippi
File name:hbtoocp.mek
Download: download sample
Signature Gozi
File size:4'009'984 bytes
First seen:2023-03-31 10:32:09 UTC
Last seen:2023-03-31 12:56:28 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 8b2be6e82e1a2f5b6a6ac4ed9979b98b (6 x Gozi)
ssdeep 49152:nMeD5RnCZX8mqviwO9j8fdh7H3ZNaaA3rA0Odlm6wqjpHWmnHp4E14XQNqrHt+T:MS5c2A9jCdh7XZNaAlZWmnf4
Threatray 6 similar samples on MalwareBazaar
TLSH T17206AE47E3A791ECC5A7C4708777F373F634381851346D776680EAB03DA6E501A0ABAA
TrID 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
26.1% (.EXE) Win64 Executable (generic) (10523/12/4)
12.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
5.1% (.ICL) Windows Icons Library (generic) (2059/9)
5.0% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Anonymous
Tags:BR-2963 exe Gozi Ursnif

Intelligence


File Origin
# of uploads :
6
# of downloads :
364
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
hbtoocp.mek
Verdict:
No threats detected
Analysis date:
2023-03-31 10:34:31 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
MeasuringTime
EvasionQueryPerformanceCounter
EvasionGetTickCount
Verdict:
No Threat
Threat level:
  2/10
Confidence:
86%
Tags:
anti-debug
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
4 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
2016f2e0e206823eab06ef55dd36d15e882fb4b7d241c2148617781a36c20e84
MD5 hash:
46e8064942475e4edcd7af3ec42ca9ef
SHA1 hash:
1c81cbc28336fa62d04c43fac193e8ed09a9bef8
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments