MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d6ff7c9aa8e9de22775814ed09222ae41d7ba306a3f4dad7634fd67eed6357d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2d6ff7c9aa8e9de22775814ed09222ae41d7ba306a3f4dad7634fd67eed6357d
SHA3-384 hash: cc35ecb62f656647f014922657c93fa17ddfb3c4ef2be4e29eb19d1e07b4b78e03f15c220a6a903e80aed3ba80226283
SHA1 hash: a516bf3818077a8819d72cb8f54e7ef4fe6a9c56
MD5 hash: d83ea2598f821b5703241f200452902e
humanhash: coffee-georgia-oven-oscar
File name:bespokemerchandises.com_wrong__39B7Ai1.exe.malw
Download: download sample
Signature Gozi
File size:334'852 bytes
First seen:2020-05-21 13:33:35 UTC
Last seen:2020-05-21 16:36:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c8c95a8437da5797cf192c4cf27b186f (327 x Gozi)
ssdeep 3072:leYLrN2UApXRBZaKBEd/UslN0r//a0tziOOdltWdnDhNuJ:4Y9peR+KBjziOOPtWdnDvu
TLSH 7E647691A953DF7DD09C25B6E5ED0B0610A2F4284F078B976E180D703FA3EA2E69435F
Reporter ov3rflow1
Tags:malw

Intelligence


File Origin
# of uploads :
2
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2020-05-21 22:05:42 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments