MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5831ebc72dc810c036fa0c1dc85e17490ebfe2f7379b9573f99d47817b9eb42c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 5831ebc72dc810c036fa0c1dc85e17490ebfe2f7379b9573f99d47817b9eb42c
SHA3-384 hash: 0f6f455efddd615d3dacfc105883a66c3eca11edfa642b3f38e804b06b1e2e3f76fe186de5bd46497cb0804cc262a12e
SHA1 hash: 592380317ff6d62338eeedf0f87b2937316c8e33
MD5 hash: c33644c4f82a0c81ebc17e8c47ff2151
humanhash: kentucky-beryllium-video-three
File name:60daf82a3cb4e.dll
Download: download sample
Signature Gozi
File size:368'640 bytes
First seen:2021-06-29 10:40:05 UTC
Last seen:2021-07-14 13:44:52 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 38e6018bca9be3803f6229dc64034399 (1 x Gozi)
ssdeep 6144:hpdZUvvYJLqfQCZU5KgF/LJyAw1cDtmikXX4uBbB:vavYJrzyAMSlkn4u/
Threatray 589 similar samples on MalwareBazaar
TLSH A8746C18B640E434CAF322B74F68D6C5277878A44B708ACF76E86A5F5F794D36230792
Reporter JAMESWT_WT
Tags:brt dll geo Gozi isfb ITA Ursnif

Intelligence


File Origin
# of uploads :
4
# of downloads :
754
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 441703 Sample: 60daf82a3cb4e.dll Startdate: 29/06/2021 Architecture: WINDOWS Score: 48 19 Multi AV Scanner detection for submitted file 2->19 7 loaddll32.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        15 2 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:8877 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
outlook.com
ghjakappoppepeodkd.website
hteadclsspdkmdasd.live
Unpacked files
SH256 hash:
81219f549002bea25201e1d37a161337f4b0a0b347f31198179cf0dcddb6c8f4
MD5 hash:
839695024c0d9cb9407fcc52693191b6
SHA1 hash:
e66394211c38836f3aef314299b0768b9ed82f0a
Detections:
win_isfb_auto
SH256 hash:
5831ebc72dc810c036fa0c1dc85e17490ebfe2f7379b9573f99d47817b9eb42c
MD5 hash:
c33644c4f82a0c81ebc17e8c47ff2151
SHA1 hash:
592380317ff6d62338eeedf0f87b2937316c8e33
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments