MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 12
| SHA256 hash: | 325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7 |
|---|---|
| SHA3-384 hash: | 8ae74d8aace16f5c43453abcbb3a188681ce7b176037c8e6aef45e11d541cafe4ff72c8707eee0265158903f766a2ad2 |
| SHA1 hash: | 07ce0da778545abed3755151950c068299decfa7 |
| MD5 hash: | ae85c25efdd62bed6e2c3ed12a22a217 |
| humanhash: | fix-fanta-arkansas-wolfram |
| File name: | 6424024a060bf.tiff |
| Download: | download sample |
| Signature | Gozi |
| File size: | 628'224 bytes |
| First seen: | 2023-03-29 09:18:27 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 45daeb6ee656a925c2836c6d4abde1b1 (2 x Gozi) |
| ssdeep | 12288:T0UQoMETWK5TpM7vBzCpgbiH4tDjwRQm3WG5Tms:ZQoMETWK5Te79CpgbiH4xjwRBW5s |
| TLSH | T196D43B66E60395F4D91705F1054BFBFBA921DB0A84328C6FE388CEA0AFF5C32159D625 |
| TrID | 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 12.7% (.EXE) Win64 Executable (generic) (10523/12/4) 7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.1% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| Reporter | |
| Tags: | dll Gozi |
Intelligence
File Origin
# of uploads :
1
# of downloads :
254
Origin country :
ITVendor Threat Intelligence
Detection:
UrsnifV3
Result
Verdict:
Malware
Maliciousness:
Behaviour
Сreating synchronization primitives
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
anti-debug anti-vm packed
Verdict:
Malicious
Labled as:
Win/malicious_confidence_60%
Malware family:
Ursnif
Verdict:
Malicious
Result
Threat name:
Ursnif
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Early bird code injection technique detected
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking system information)
Malicious sample detected (through community Yara rule)
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Detection(s):
Suspicious file
Result
Malware family:
gozi
Score:
10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi
Malware Config
C2 Extraction:
https://config.edge.skype.com
91.215.85.186
91.215.85.186
Unpacked files
SH256 hash:
db67f7fd39b5c3f6bfb4b866a05a4ae7a18fa253cd01f32b23c083c4a4338aa3
MD5 hash:
6a81bc6d604453df6996b7ce95325752
SHA1 hash:
ddb0089ec74ad78e4f09154e1aff812272476c0c
SH256 hash:
f1835e49f47a7833c69f30e70a1b8b7804feb1a854734e60c97892dc20ad84f2
MD5 hash:
a457b534727df3bb81988e77ad55329b
SHA1 hash:
ca3e7d040bfc8db224f21dcd884c4b397906a941
SH256 hash:
325f7b8b082c01f0b950f001c0bef4d0fc3bb5cef1a8a74bc9dc60be3bdc32e7
MD5 hash:
ae85c25efdd62bed6e2c3ed12a22a217
SHA1 hash:
07ce0da778545abed3755151950c068299decfa7
Malware family:
Ursnif
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.