🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7
SHA3-384 hash: 8ae74d8aace16f5c43453abcbb3a188681ce7b176037c8e6aef45e11d541cafe4ff72c8707eee0265158903f766a2ad2
SHA1 hash: 07ce0da778545abed3755151950c068299decfa7
MD5 hash: ae85c25efdd62bed6e2c3ed12a22a217
humanhash: fix-fanta-arkansas-wolfram
File name:6424024a060bf.tiff
Download: download sample
Signature Gozi
File size:628'224 bytes
First seen:2023-03-29 09:18:27 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 45daeb6ee656a925c2836c6d4abde1b1 (2 x Gozi)
ssdeep 12288:T0UQoMETWK5TpM7vBzCpgbiH4tDjwRQm3WG5Tms:ZQoMETWK5Te79CpgbiH4xjwRBW5s
TLSH T196D43B66E60395F4D91705F1054BFBFBA921DB0A84328C6FE388CEA0AFF5C32159D625
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10523/12/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Reporter proxylife
Tags:dll Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
254
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug anti-vm packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Early bird code injection technique detected
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking system information)
Malicious sample detected (through community Yara rule)
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi
Malware Config
C2 Extraction:
https://config.edge.skype.com
91.215.85.186
Unpacked files
SH256 hash:
db67f7fd39b5c3f6bfb4b866a05a4ae7a18fa253cd01f32b23c083c4a4338aa3
MD5 hash:
6a81bc6d604453df6996b7ce95325752
SHA1 hash:
ddb0089ec74ad78e4f09154e1aff812272476c0c
SH256 hash:
f1835e49f47a7833c69f30e70a1b8b7804feb1a854734e60c97892dc20ad84f2
MD5 hash:
a457b534727df3bb81988e77ad55329b
SHA1 hash:
ca3e7d040bfc8db224f21dcd884c4b397906a941
SH256 hash:
325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7
MD5 hash:
ae85c25efdd62bed6e2c3ed12a22a217
SHA1 hash:
07ce0da778545abed3755151950c068299decfa7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

DLL dll 325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7

(this sample)

  
Delivery method
Distributed via web download

Comments