🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 50810e4696dd075ca23349e3e1c3a87fc7b46ab89f4b1eb093a5cfb74f84cc51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 50810e4696dd075ca23349e3e1c3a87fc7b46ab89f4b1eb093a5cfb74f84cc51
SHA3-384 hash: e9d5e5ac2ba47967b3ab735293d33436cf751d5c0ba35c357d8a0f105d1d0d253e842bdb0e5de230871bdc010a54a18e
SHA1 hash: 19307cd55c54e8d4db3666fd11d69f2fe27942c0
MD5 hash: f6d0b9617405f35bb846d671edda75d3
humanhash: michigan-solar-tennessee-blue
File name:dw4qdkjbqwijhdhbwqjid.iso
Download: download sample
Signature Gozi
File size:3'023'360 bytes
First seen:2023-07-12 04:02:26 UTC
Last seen:2024-09-03 06:50:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d8cf501f2ead6a968abf3df1e5f5d366 (3 x Gozi, 2 x WikiLoader)
ssdeep 49152:jEFD9UfWifI29mfKQnMg2XgEl7MV/yTm:7U9yTm
TLSH T1D6E54A4562AD84E1E07B90BDD6DFBA1FF5213408071096CB06E44A9D6F33FE94BBA721
TrID 89.2% (.CPL) Windows Control Panel Item (generic) (197083/11/60)
4.7% (.EXE) Win64 Executable (generic) (10523/12/4)
2.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.9% (.ICL) Windows Icons Library (generic) (2059/9)
0.9% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter JAMESWT_WT
Tags:exe Gozi iso LLC-250215 payload WikiLoader WikiLoaderGozi

Intelligence


File Origin
# of uploads :
3
# of downloads :
370
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
dw4qdkjbqwijhdhbwqjid.iso
Verdict:
No threats detected
Analysis date:
2023-07-12 04:03:49 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
greyware masquerade
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2023-07-12 04:03:05 UTC
File Type:
PE+ (Dll)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
50810e4696dd075ca23349e3e1c3a87fc7b46ab89f4b1eb093a5cfb74f84cc51
MD5 hash:
f6d0b9617405f35bb846d671edda75d3
SHA1 hash:
19307cd55c54e8d4db3666fd11d69f2fe27942c0
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

Executable exe 50810e4696dd075ca23349e3e1c3a87fc7b46ab89f4b1eb093a5cfb74f84cc51

(this sample)

  
Delivery method
Distributed via web download

Comments