🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ffc3c329ace3bf652db9d8fdcdb7ef19fd1563d39b3ef3934e0170209f03382. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 3ffc3c329ace3bf652db9d8fdcdb7ef19fd1563d39b3ef3934e0170209f03382
SHA3-384 hash: b0f07ed2b6653edde7afbb7e2ed98863b8167f2d0a8de6522a39698286fc131b0752e2f36425c66d0eed380714117867
SHA1 hash: fc60327c142041f4486a6a814fc2c8059bc9042c
MD5 hash: e8f17a3011cf011942a5ed07c7aaaaf8
humanhash: glucose-beer-lima-michigan
File name:6419861983e7f.png
Download: download sample
Signature Gozi
File size:222'208 bytes
First seen:2023-03-21 10:26:03 UTC
Last seen:2023-03-21 10:28:52 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash d43c0ee666438620f4b82edabd94a02a (1 x Gozi)
ssdeep 3072:7XFEOXctZScgJKooUngEKpXXaAFwxokUiZQxvudEGyWGKYu:zF5apg8LUngEKp65okUiZM0yWGT
Threatray 443 similar samples on MalwareBazaar
TLSH T1C0243744DE375DF4D9E306731146FE3AF6365C829B2A4FA8F742AD33E86592930046E8
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10523/12/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
File icon (PE):PE icon
dhash icon 78f8e0c2d288c9b2 (1 x Gozi, 1 x Cutwail)
Reporter proxylife
Tags:5050 dll fattndl-site GLS Gozi Ursnif

Intelligence


File Origin
# of uploads :
2
# of downloads :
272
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug anti-vm packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Early bird code injection technique detected
Found API chain indicative of debugger detection
Malicious sample detected (through community Yara rule)
Queues an APC in another process (thread injection)
Sigma detected: Execute DLL with spoofed extension
Sigma detected: Register DLL with spoofed extension
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Gozi
Status:
Malicious
First seen:
2023-03-21 10:27:07 UTC
File Type:
PE (Dll)
Extracted files:
2
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi
Malware Config
C2 Extraction:
https://config.edge.skype.com
91.215.85.201
Unpacked files
SH256 hash:
2b4ba2f801ad29a4b951c3e8c53a2565062224af6a3d1783d3eb53b472836613
MD5 hash:
278a6d8598f10e6bb3841ff5bfcd6d47
SHA1 hash:
eaec0fe838c7ecc028c1050f6b093c0ea07b8f42
SH256 hash:
69d646441885a01d2203c17d5b38c1772d0f8cb76d0a43d33d143e7a0b13f6f8
MD5 hash:
4984b442edb1cf12523faec4ad99c4ef
SHA1 hash:
5387e3fad9ee5d4e894f9ed8c6867c341f6dab11
SH256 hash:
3ffc3c329ace3bf652db9d8fdcdb7ef19fd1563d39b3ef3934e0170209f03382
MD5 hash:
e8f17a3011cf011942a5ed07c7aaaaf8
SHA1 hash:
fc60327c142041f4486a6a814fc2c8059bc9042c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments