MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3ffc3c329ace3bf652db9d8fdcdb7ef19fd1563d39b3ef3934e0170209f03382. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 11
| SHA256 hash: | 3ffc3c329ace3bf652db9d8fdcdb7ef19fd1563d39b3ef3934e0170209f03382 |
|---|---|
| SHA3-384 hash: | b0f07ed2b6653edde7afbb7e2ed98863b8167f2d0a8de6522a39698286fc131b0752e2f36425c66d0eed380714117867 |
| SHA1 hash: | fc60327c142041f4486a6a814fc2c8059bc9042c |
| MD5 hash: | e8f17a3011cf011942a5ed07c7aaaaf8 |
| humanhash: | glucose-beer-lima-michigan |
| File name: | 6419861983e7f.png |
| Download: | download sample |
| Signature | Gozi |
| File size: | 222'208 bytes |
| First seen: | 2023-03-21 10:26:03 UTC |
| Last seen: | 2023-03-21 10:28:52 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | d43c0ee666438620f4b82edabd94a02a (1 x Gozi) |
| ssdeep | 3072:7XFEOXctZScgJKooUngEKpXXaAFwxokUiZQxvudEGyWGKYu:zF5apg8LUngEKp65okUiZM0yWGT |
| Threatray | 443 similar samples on MalwareBazaar |
| TLSH | T1C0243744DE375DF4D9E306731146FE3AF6365C829B2A4FA8F742AD33E86592930046E8 |
| TrID | 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 12.7% (.EXE) Win64 Executable (generic) (10523/12/4) 7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.1% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| File icon (PE): | |
| dhash icon | 78f8e0c2d288c9b2 (1 x Gozi, 1 x Cutwail) |
| Reporter | |
| Tags: | 5050 dll fattndl-site GLS Gozi Ursnif |
Intelligence
File Origin
# of uploads :
2
# of downloads :
272
Origin country :
ITVendor Threat Intelligence
Detection:
n/a
Result
Verdict:
Malware
Maliciousness:
Behaviour
Searching for the window
Сreating synchronization primitives
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
anti-debug anti-vm packed
Verdict:
Malicious
Labled as:
Win/malicious_confidence_60%
Verdict:
Malicious
Result
Threat name:
Ursnif
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Early bird code injection technique detected
Found API chain indicative of debugger detection
Malicious sample detected (through community Yara rule)
Queues an APC in another process (thread injection)
Sigma detected: Execute DLL with spoofed extension
Sigma detected: Register DLL with spoofed extension
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Gozi
Status:
Malicious
First seen:
2023-03-21 10:27:07 UTC
File Type:
PE (Dll)
Extracted files:
2
AV detection:
15 of 24 (62.50%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
gozi
Similar samples:
+ 433 additional samples on MalwareBazaar
Result
Malware family:
gozi
Score:
10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi
Malware Config
C2 Extraction:
https://config.edge.skype.com
91.215.85.201
91.215.85.201
Unpacked files
SH256 hash:
2b4ba2f801ad29a4b951c3e8c53a2565062224af6a3d1783d3eb53b472836613
MD5 hash:
278a6d8598f10e6bb3841ff5bfcd6d47
SHA1 hash:
eaec0fe838c7ecc028c1050f6b093c0ea07b8f42
SH256 hash:
69d646441885a01d2203c17d5b38c1772d0f8cb76d0a43d33d143e7a0b13f6f8
MD5 hash:
4984b442edb1cf12523faec4ad99c4ef
SHA1 hash:
5387e3fad9ee5d4e894f9ed8c6867c341f6dab11
SH256 hash:
3ffc3c329ace3bf652db9d8fdcdb7ef19fd1563d39b3ef3934e0170209f03382
MD5 hash:
e8f17a3011cf011942a5ed07c7aaaaf8
SHA1 hash:
fc60327c142041f4486a6a814fc2c8059bc9042c
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.