🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54aa0629030dd73c87c439e09e0dda942775da54b61ffde9844ca2bd2cfb07a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 54aa0629030dd73c87c439e09e0dda942775da54b61ffde9844ca2bd2cfb07a7
SHA3-384 hash: 5957c87b42a5339073aec66a371ba46bcdb56b30bce484915163514c7acf0b5eb71eaa3174e9836ac5e12af2bf7a1332
SHA1 hash: 28d8a6702963b8f0c69c771ae1a46fd2d6f2a07f
MD5 hash: 31a73036058b7ffae871d2ec5fb3e9f8
humanhash: don-five-idaho-nuts
File name:FM85.zip
Download: download sample
Signature Gozi
File size:343'717 bytes
First seen:2022-12-15 16:45:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: PM11
ssdeep 6144:N0tXiLwNB/T34yNbFCUiZxVhiqI7vhutKMjWmtCuIras/IekiXC4I+jkVc92aojm:Kqm6QaZxbiqccKCWmtJIOs7HC4IVLaym
TLSH T1A67423636126A95C67E772C4EFCE25931D320D49A4CC0F80481EE736B09D5FEA5F1663
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:50000 Gozi pw-PM11 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
IE IE
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:registrants.cmd
File size:203 bytes
SHA256 hash: 61794da96a047bf99eb8ef51896e872d79d77a4760c056ff5ea9e749a263893d
MD5 hash: 0808d161760884c2d0b2ea3443740806
MIME type:text/plain
Signature Gozi
File name:VV.lnk
File size:1'723 bytes
SHA256 hash: 9c6ce72957b412592a5c8d7d0324a53f2a7a77ca94773549494aecf18c83d050
MD5 hash: 41fa8bb4ec4d94e6c329583a8d3f93b1
MIME type:application/octet-stream
Signature Gozi
File name:fizzy.sql
File size:593'920 bytes
SHA256 hash: 7ad0db9da1c28e6d12826b846ee3c82bda649e00d717cb2c4aefeaed56ea48ce
MD5 hash: 7272aaeea39e988faaf3a5aebc6c7867
MIME type:application/x-dosexec
Signature Gozi
File name:enfeebles.cmd
File size:275 bytes
SHA256 hash: 0e6761acc6a4da6c360730da8c1a3a03e782058c51bb95e47946f52a7524bada
MD5 hash: d612a00764fec9d6de3ea90f486e273b
MIME type:text/plain
Signature Gozi
File name:aerate.png
File size:16'287 bytes
SHA256 hash: aabd67df6c36dd10932b8b59a31c88771f82649910d9f428291c10ade46aa78f
MD5 hash: 060266b8732519bc95b5c6ea4f41e44b
MIME type:image/png
Signature Gozi
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:50000 banker isfb trojan
Behaviour
Runs ping.exe
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Gozi
Malware Config
C2 Extraction:
http://confisg.edges.skype.com
http://108.61.165.145
http://37.120.222.23
http://194.76.224.234
http://176.10.111.47
https://confisg.edges.skype.com
http://79.132.128.146
http://176.10.119.229
http://176.10.111.45
http://79.132.128.151
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PassProtected_ZIP_ISO_file
Author:_jc
Description:Detects container formats commonly smuggled through password-protected zips
Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

zip 54aa0629030dd73c87c439e09e0dda942775da54b61ffde9844ca2bd2cfb07a7

(this sample)

  
Delivery method
Distributed via web download

Comments