MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 32b222165a61978b9d981cbd77eee2c24d7d366021ad3abfcfcd052d7a6e8d4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 32b222165a61978b9d981cbd77eee2c24d7d366021ad3abfcfcd052d7a6e8d4e
SHA3-384 hash: a42d7447a24f92379a0e72e58aded7880850ecd5c9902b5d1e85537b0306bacc22e02f3f39f5d716000fc7daba63a021
SHA1 hash: c7e5add4ba47088a6ebd3ac7c8c3cd3f619d4e6f
MD5 hash: 5e8337608ddfcc8db454619639098501
humanhash: moon-butter-kansas-yellow
File name:SecuriteInfo.com.Trojan.Gozi.2177.22380.17981
Download: download sample
File size:2'883'715 bytes
First seen:2026-07-22 08:11:57 UTC
Last seen:2026-07-22 08:42:51 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 46ce5c12b293febbeb513b196aa7f843 (42 x GuLoader, 21 x RemcosRAT, 12 x AgentTesla)
ssdeep 49152:4oiPj+/yE64TV/PS1c4c/G/nIRDRGdLRcoknjz8BMi9ZEEdqRHp7AR3pY0+AAtNa:4owj6tzVH4c/GAbGdL72jzl2fccrYtA5
TLSH T195D533709370569CDA014937A821BCF78784BD2BA407F82E17746D14772B3CA9A7AF6C
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon f86eeae6b696c6cc (6 x AgentTesla, 5 x SliverFox, 3 x LummaStealer)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
166
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
chrome-windows.ru
Verdict:
Malicious activity
Analysis date:
2026-05-26 07:17:40 UTC
Tags:
websocket loader stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file in the Program Files subdirectories
Creating a window
Creating a file
Deleting a recently created file
Сreating synchronization primitives
Creating a service
Moving a file to the Program Files subdirectory
Launching a service
Searching for synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Enabling autorun for a service
Enabling autorun by creating a file
Verdict:
Adware
File Type:
exe x32
First seen:
2026-02-12T00:26:00Z UTC
Last seen:
2026-07-22T05:06:00Z UTC
Hits:
~10000
Gathering data
Threat name:
Win32.Trojan.YandexBundled
Status:
Suspicious
First seen:
2026-02-13 02:27:27 UTC
File Type:
PE (Exe)
Extracted files:
347
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery persistence privilege_escalation spyware stealer trojan
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Checks installed software on the system
Checks whether UAC is enabled
Checks computer location settings
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Boot or Logon Autostart Execution: Active Setup
Downloads MZ/PE file
Unpacked files
SH256 hash:
32b222165a61978b9d981cbd77eee2c24d7d366021ad3abfcfcd052d7a6e8d4e
MD5 hash:
5e8337608ddfcc8db454619639098501
SHA1 hash:
c7e5add4ba47088a6ebd3ac7c8c3cd3f619d4e6f
SH256 hash:
810e9879fdb18d0a5d68cd455b7187c62eb44fe585346a34f17b8802ad065482
MD5 hash:
66359e7e445803478383f3d2d35e9c6b
SHA1 hash:
39fadda30aa9ccca73314db31fc8aaceef126393
SH256 hash:
83005624a3c515e8e4454a416693ba0fbf384ff5ea0e1471f520dfae790d4ab7
MD5 hash:
38f2b22967573a872426d05bdc1a1a70
SHA1 hash:
ecae471eb4e515e1006fce645a82b70c8acda451
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:NSIS
Author:kevoreilly
Description:NSIS Integrity Check function

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 32b222165a61978b9d981cbd77eee2c24d7d366021ad3abfcfcd052d7a6e8d4e

(this sample)

  
Delivery method
Distributed via web download

Comments