🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2110da33cfe1eaecd05be82b4717cd7381665f5c729a67c7671e612bae06fc24. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 2110da33cfe1eaecd05be82b4717cd7381665f5c729a67c7671e612bae06fc24
SHA3-384 hash: f412923acd171059cf7c9749e138809626360ae6132967bcf5efa0053619cbe85490ea83c4666488fdbb8494b296af3a
SHA1 hash: 535a87459f80f0f73ae6807a4c1b9999ec22c146
MD5 hash: aa680f5e07148fdbef3e79ea07e11846
humanhash: virginia-oranges-paris-fifteen
File name:Azienda.zip
Download: download sample
Signature Gozi
File size:320 bytes
First seen:2023-10-12 13:01:33 UTC
Last seen:2023-10-12 13:51:20 UTC
File type: zip
MIME type:application/zip
ssdeep 6:5jwEontLuErnw+SMNILqWhk7Qi/carddPUTpdwnxn+tYEonBO9L6uKKP+ls:5jwfntLPnmpLqWhk7dUaDPUl0TfnBATJ
TLSH T1E6E0723288190000C20B863C23838301C2428ACF3A10C8EBCA4B0B2D0AB3A8A2E8030B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter Mangusta
Tags:agenziaentrate Gozi Ursnif zip zip url

Intelligence


File Origin
# of uploads :
2
# of downloads :
167
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Azienda.url
File size:193 bytes
SHA256 hash: 589deb6665a90960cfbe3db62f3477f9a2087a2b2eb03d1a19ea69374a9eb34e
MD5 hash: 385b2d1cc0f48c9b113009619258b210
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Threat name:
Shortcut.Trojan.MalLink
Status:
Malicious
First seen:
2023-10-12 13:02:05 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Loads dropped DLL
Blocklisted process makes network request
Gozi
Malware Config
C2 Extraction:
fotexion.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Methodology_Suspicious_Shortcut_SMB_URL
Author:@itsreallynick (Nick Carr), @QW5kcmV3 (Andrew Thompson)
Description:Detects remote SMB path for .URL persistence
Reference:https://twitter.com/cglyer/status/1176184798248919044

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

zip 2110da33cfe1eaecd05be82b4717cd7381665f5c729a67c7671e612bae06fc24

(this sample)

  
Delivery method
Distributed via web download

Comments