MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c1cfaeb1cb2168477f7e90e671a7ba182cb95b4845c0cf4c44f5809edcd5cc2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments 1

SHA256 hash: 2c1cfaeb1cb2168477f7e90e671a7ba182cb95b4845c0cf4c44f5809edcd5cc2
SHA3-384 hash: 30bafd2f5afd03e3c97eeff844d34304dd2ecbbb002598e368ee3da068c8d2e58d8c9c2ee46becf005f253a4eead6278
SHA1 hash: 2c0ccd89ed239e26b53712481bd6bad3b64c2cd8
MD5 hash: 0852cea14762e26a7ab75d58524a2c47
humanhash: butter-saturn-fix-indigo
File name:0852cea14762e26a7ab75d58524a2c47
Download: download sample
Signature Gozi
File size:700'112 bytes
First seen:2021-11-17 03:04:15 UTC
Last seen:2021-11-17 05:14:14 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c568566346c64cd9311c27510500b5da (1 x Gozi)
ssdeep 12288:1bI55XSfTqFihNeQiITStNa879WxC96dMG5Hllvv/eQiITStNa879WxC96dMGt:1OXpiRS+879CJ5HllvhS+879CJt
TLSH T106E4D003729EBCB3D072463117BAC7F1572DE8590A25CA9F63D41A2E4E2C5D37A21F62
File icon (PE):PE icon
dhash icon f0968ee8aae8e8b2 (9 x Urelas, 5 x HermeticWiper, 4 x Starcat)
Reporter zbetcheckin
Tags:32 exe Gozi

Intelligence


File Origin
# of uploads :
2
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
http://felionaris.com/xs/mypc.exe
Verdict:
Suspicious activity
Analysis date:
2021-11-17 03:49:55 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
greyware overlay packed virus
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
ReflectiveLoader
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contain functionality to detect virtual machines
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Writes or reads registry keys via WMI
Yara detected ReflectiveLoader
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-11-16 23:53:59 UTC
AV detection:
24 of 28 (85.71%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
2c1cfaeb1cb2168477f7e90e671a7ba182cb95b4845c0cf4c44f5809edcd5cc2
MD5 hash:
0852cea14762e26a7ab75d58524a2c47
SHA1 hash:
2c0ccd89ed239e26b53712481bd6bad3b64c2cd8
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

Executable exe 2c1cfaeb1cb2168477f7e90e671a7ba182cb95b4845c0cf4c44f5809edcd5cc2

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-11-17 03:04:18 UTC

url : hxxp://felionaris.com/xs/mypc.exe