🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fc5fe464bee34e45e7d88c634a122164f0f2b3a78ae46a8d540eee17cf13647. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA 11 File information Comments

SHA256 hash: 4fc5fe464bee34e45e7d88c634a122164f0f2b3a78ae46a8d540eee17cf13647
SHA3-384 hash: 026125f0590ebe2293e872e64c06784bff918041b2188baad2fd9f96e6bcdcf4abb0d46d517cde1a0566e32b73cff4cf
SHA1 hash: edc0f186ee5dfb5b05d8d57d283cc49f688a6afc
MD5 hash: 14cb7db8dbd6760facc522bee181071f
humanhash: five-social-jersey-iowa
File name:5353.iso
Download: download sample
Signature Gozi
File size:428'032 bytes
First seen:2022-10-20 12:25:50 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:wNbMYzwhwZwcwvOqHYHHDOcYw9wi5eOlGHHHHuOUwLmwbj26rj+:QzwhwZwcwXHYHHmw9wqdGHHHHMwLmQjS
TLSH T1E0946C27E34403B1C56303759A8E71D1F72684393361DA54B89E52ED33129FECA7BAE8
TrID 99.0% (.NULL) null bytes (2048000/1)
0.5% (.WAR) Warcraft II game data archive (12007/4/6)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter JAMESWT_WT
Tags:Gozi isfb iso pw 758493 Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
n/a
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:highlighted.cmd
File size:378 bytes
SHA256 hash: 9b1f31bdc9ae8596f6cbf32f213857d74aa0801caf8bcf2f3b23ac9efb0d8f29
MD5 hash: 5ba9ba2fdc982323061d2fa8977b73e2
MIME type:text/x-msdos-batch
Signature Gozi
File name:buggies.txt
File size:218'393 bytes
SHA256 hash: db86c041ab135347ea6c7dcd7acd658ef1d74039690bd754d0f31ef05ce8bf6b
MD5 hash: 51dddb40ac822a7b9aa35c7168e3e88e
MIME type:text/plain
Signature Gozi
File name:5353.lnk
File size:1'831 bytes
SHA256 hash: 3217a3d5115cd2aefb82497017ed391c9400be479e56b9a6aa0e40f66da8cdcb
MD5 hash: ab707348e10bb475ae3da7dbc3a3e791
MIME type:application/octet-stream
Signature Gozi
File name:reservations.3ds
File size:118'784 bytes
SHA256 hash: 4c0ccba038ff513555223a880da3760a974b0479fe6cf0e823f08774ecd0d9ba
MD5 hash: 17ddc738604a040176b85c80173c5090
MIME type:application/x-dosexec
Signature Gozi
File name:bray.png
File size:27'560 bytes
SHA256 hash: b3efcbd17ef6c03bd93e13cff7ca5ab9be0e70b72c409d62a3911af8939cf35f
MD5 hash: db8186958edb6e81844086af223e9ae0
MIME type:image/png
Signature Gozi
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
context-iso packed
Threat name:
Win32.Infostealer.QBot
Status:
Malicious
First seen:
2022-10-18 21:23:40 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
12 of 41 (29.27%)
Threat level:
  5/5
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:5000 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Loads dropped DLL
Blocklisted process makes network request
Executes dropped EXE
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
config.edge.skype.com
onlinetwork.top
linetwork.top
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:iso_lnk
Author:tdawg
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:Qakbot_IsoCampaign
Author:Malhuters
Description:Qakbot New Campaign ISO
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious
Rule name:SUSP_VBS_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contain VBS functions
Reference:Internal Research
Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments