🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 511e23ad034cd019805b2c560e3d761ab8d1148557d7632d9700aabd757438de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 511e23ad034cd019805b2c560e3d761ab8d1148557d7632d9700aabd757438de
SHA3-384 hash: 745a0614abe8a6b3ee031e61dfb1f7cb0bd521c1a1fa7bce189fd0cfd2d74e484b3a29312de3dc1f5dd3cda57e16f6dc
SHA1 hash: 865e145795f5ff9efceca796062a9e7f930e279a
MD5 hash: b3c14105b2e6a235a1f789ffb5395fd3
humanhash: five-zebra-early-island
File name:scarica (2).exe
Download: download sample
Signature Gozi
File size:249'771 bytes
First seen:2023-01-25 11:33:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 13743b83cdbed1b091d19518975401a2 (13 x Smoke Loader, 4 x Gozi, 1 x ArkeiStealer)
ssdeep 6144:pCxLvYy7IVQf2JF2qNYihWY8gVmwCOaM8rHtQK/fu0:MxB7IVQeSKYihT8gVmw05tQKXu0
TLSH T10F34CE836EE4BC61C9264A328D1FCBEC76DDF9025E1867271739DA2F25B03B5C672118
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 080808480c180800 (3 x Gozi)
Reporter JAMESWT_WT
Tags:agenziaentrate exe Gozi Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
268
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
greyware overlay packed
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.RedLine
Status:
Malicious
First seen:
2023-01-25 11:32:19 UTC
File Type:
PE (Exe)
Extracted files:
44
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
511e23ad034cd019805b2c560e3d761ab8d1148557d7632d9700aabd757438de
MD5 hash:
b3c14105b2e6a235a1f789ffb5395fd3
SHA1 hash:
865e145795f5ff9efceca796062a9e7f930e279a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments