🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 569b699b192f8e67cf1d59ea730384c3b7a5747b76318829c83c71afebccd352. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 569b699b192f8e67cf1d59ea730384c3b7a5747b76318829c83c71afebccd352
SHA3-384 hash: 7ed3c15d3475371ba3e721c734485d86492bcc518c86502a825e08384c94a54692231cd765bf1e09efee917548c6922f
SHA1 hash: 28084821f87f20150630ceed4e3f2315c94eecfd
MD5 hash: 13e2665c7bbdc945eee61fb9e77cde09
humanhash: timing-green-xray-mirror
File name:ministro.zip
Download: download sample
Signature Gozi
File size:470 bytes
First seen:2023-01-05 12:04:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12:5jVbzWnbdWvex8jLBsWHBXERQdknuJT6sWYdp95:9VbzWbQVfyFKQuJJWYT
TLSH T16FF02222E88333A7C77FD5B830D96B14693EE35944A1001BE42A7170EE47AAD8678F54
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:31-41-44-154 agenziaentrate Gozi mise SMB Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:ministro.url
File size:195 bytes
SHA256 hash: 5d02c3a289d1f3ba0f86db0aa058337cbd0830d922dfa8a3bc236d9bf80eafba
MD5 hash: 894f098e6e0691c2cdc5cf45fb94ce0d
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
remote
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:7702 banker isfb trojan
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Gozi
Malware Config
C2 Extraction:
checklist.skype.com
62.173.138.160
31.41.44.122
193.0.178.141
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Methodology_Suspicious_Shortcut_SMB_URL
Author:@itsreallynick (Nick Carr), @QW5kcmV3 (Andrew Thompson)
Description:Detects remote SMB path for .URL persistence
Reference:https://twitter.com/cglyer/status/1176184798248919044

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments