🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 29e8bf78ac6bfd95c21e2cbb06a0a9d8088fe9e759673c81eeadd96d681b73ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 11


Intelligence 11 IOCs YARA 1 File information Comments

SHA256 hash: 29e8bf78ac6bfd95c21e2cbb06a0a9d8088fe9e759673c81eeadd96d681b73ed
SHA3-384 hash: 3423ce7636976e27d500ccafd31f5cbdb133017cd27cc6dd40578fb4c2b3e63f99be9de94d1ceaede5a12e2b0c486db9
SHA1 hash: dbe5b4db4b61702f523b86be1d73b742b8d120eb
MD5 hash: 5e3bf7458c6d8e6e880db72fcdf61f3a
humanhash: oven-nineteen-artist-bravo
File name:freeofice.dll
Download: download sample
Signature Gozi
File size:344'064 bytes
First seen:2022-04-13 08:53:38 UTC
Last seen:2022-04-25 11:47:00 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 37987333ff274c9bd7aa5aebc79b81a2 (1 x Gozi)
ssdeep 6144:3VYe1K4PEIBn308Yw0PY6xLBhN4b8H/I9TS4a+KqKwnhVyCTs:ies4c0E8f09Dm4QB1KdwhVyCTs
Threatray 494 similar samples on MalwareBazaar
TLSH T1547412A6F5F7BD62DC1A8F7A16DA5FFE1B4C880180E58A77451C42C849AC1878FE5C1C
Reporter JAMESWT_WT
Tags:dll Gozi isfb ITA Ursnif

Intelligence


File Origin
# of uploads :
5
# of downloads :
968
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Launching a process
Searching for synchronization primitives
Creating a window
DNS request
Sending an HTTP GET request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed setupapi.dll
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking system information)
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Call by Ordinal
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 608536 Sample: freeofice.dll Startdate: 13/04/2022 Architecture: WINDOWS Score: 100 41 linkspremium.ru 2->41 65 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->65 67 Multi AV Scanner detection for domain / URL 2->67 69 Found malware configuration 2->69 71 4 other signatures 2->71 8 loaddll32.exe 7 2->8         started        12 iexplore.exe 1 53 2->12         started        14 iexplore.exe 1 54 2->14         started        16 2 other processes 2->16 signatures3 process4 dnsIp5 61 premiumlists.ru 8->61 63 nahuinado.top 8->63 77 Found evasive API chain (may stop execution after checking system information) 8->77 79 Found API chain indicative of debugger detection 8->79 81 Writes or reads registry keys via WMI 8->81 83 Writes registry values via WMI 8->83 18 cmd.exe 1 8->18         started        20 iexplore.exe 33 12->20         started        23 iexplore.exe 30 12->23         started        25 iexplore.exe 31 14->25         started        27 iexplore.exe 30 14->27         started        29 iexplore.exe 16->29         started        31 iexplore.exe 16->31         started        33 iexplore.exe 16->33         started        35 iexplore.exe 16->35         started        signatures6 process7 dnsIp8 37 rundll32.exe 6 18->37         started        43 premiumlists.ru 20->43 45 premiumlists.ru 23->45 47 nahuinado.top 62.173.149.135, 49770, 49771, 49772 SPACENET-ASInternetServiceProviderRU Russian Federation 25->47 49 31.41.46.120, 49779, 49780, 49809 ASRELINKRU Russian Federation 27->49 51 192.168.2.1 unknown unknown 27->51 53 linkspremium.ru 33->53 55 linkspremium.ru 35->55 process9 dnsIp10 57 premiumlists.ru 37->57 59 nahuinado.top 37->59 73 System process connects to network (likely due to code injection or exploit) 37->73 75 Writes registry values via WMI 37->75 signatures11
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2022-04-13 08:54:06 UTC
File Type:
PE (Dll)
AV detection:
17 of 26 (65.38%)
Threat level:
  5/5
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:7630 banker trojan
Behaviour
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
nahuinado.top
linkspremium.ru
premiumlists.ru
Unpacked files
SH256 hash:
931926d146b09f1de8cb2da7f0eaf36b52514679eb69eb859f8b01533fb18c17
MD5 hash:
a5bde37a6686a3165d1c72a58f3ebc6f
SHA1 hash:
e6aff7ee6736bfc0a3448c8be148d55e05f57923
Detections:
win_isfb_auto
SH256 hash:
cee2824fbd6aad9847e8c7790d2449bb3116eb2945861b15f129ff36efd67d57
MD5 hash:
73eab2aa32849ede37ab7613cebff3b7
SHA1 hash:
330882d6445cbcdcffadb038f8a9c1181eb362ae
SH256 hash:
29e8bf78ac6bfd95c21e2cbb06a0a9d8088fe9e759673c81eeadd96d681b73ed
MD5 hash:
5e3bf7458c6d8e6e880db72fcdf61f3a
SHA1 hash:
dbe5b4db4b61702f523b86be1d73b742b8d120eb
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

DLL dll 29e8bf78ac6bfd95c21e2cbb06a0a9d8088fe9e759673c81eeadd96d681b73ed

(this sample)

Comments