MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 67ca5cc17611a5292c116f492af8a96caebbe3539e3744daaa1f1c1a5cf72d05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 7
| SHA256 hash: | 67ca5cc17611a5292c116f492af8a96caebbe3539e3744daaa1f1c1a5cf72d05 |
|---|---|
| SHA3-384 hash: | c3ae577b1b8e9fc0983b8bfda1171af22242c9282a2f135dfd0cb75ec4a8e42022f4ef8f7875dc912ad7efbf42091431 |
| SHA1 hash: | 06710b16a700b2f86ec7b77204b7d132a83a34f0 |
| MD5 hash: | a7408cf2d8a68c9d621f04510d013c25 |
| humanhash: | tennessee-aspen-montana-december |
| File name: | 9095.dll |
| Download: | download sample |
| Signature | Gozi |
| File size: | 1'560'576 bytes |
| First seen: | 2022-01-06 10:52:59 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 709bff5b052da35274d637706fb01b1d (1 x Gozi) |
| ssdeep | 6144:C/mh48sQe3KipXDjA5d86CT9p2mxKvQCPRub+:9mVQmoEL1uQ9q |
| TLSH | T10A75097795905703E4ACCFF18BD6134A335A061EDB2BC12A1B3D906EB5B7A1AF1D9083 |
| File icon (PE): | |
| dhash icon | 74d4baacece8f0d4 (1 x Gozi) |
| Reporter | |
| Tags: | dll exe Gozi ZLoader |
Intelligence
File Origin
# of uploads :
1
# of downloads :
336
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
9095.dll
Verdict:
No threats detected
Analysis date:
2022-01-06 10:56:29 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Result
Verdict:
Clean
Maliciousness:
Behaviour
Searching for synchronization primitives
Сreating synchronization primitives
DNS request
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
greyware
Verdict:
Malicious
Result
Threat name:
Ursnif
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Rundll32 performs DNS lookup (likely malicious behavior)
Sigma detected: Suspicious Call by Ordinal
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Sleltasos
Status:
Malicious
First seen:
2021-12-03 12:17:34 UTC
File Type:
PE (Dll)
Extracted files:
29
AV detection:
22 of 28 (78.57%)
Threat level:
5/5
Result
Malware family:
gozi_ifsb
Score:
10/10
Tags:
family:gozi_ifsb botnet:9095 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
http://google.mail.com
http://392184281.com
http://592182812.com
https://392184281.com
https://592182812.com
http://392184281.com
http://592182812.com
https://392184281.com
https://592182812.com
Unpacked files
SH256 hash:
636c7a822625ae96479f07029576b1c331ed05d3a2c8f27cc358f2b77b13ab98
MD5 hash:
8ec039f5f0f9db12fc80abaf9d4790c8
SHA1 hash:
9b19518bdc3c8644606dbc3b5388786af9ef0016
Detections:
win_isfb_auto
SH256 hash:
5f8235da44a8c211db5bf5fe5d4adfcc891fb3642b03f4fc69d8399a5490f9b0
MD5 hash:
0b8939573cdcd18e56ca5272b1a8ea85
SHA1 hash:
2ea850f817ebb487e25c13c3f552f248bf3915cf
Detections:
win_isfb_auto
SH256 hash:
67ca5cc17611a5292c116f492af8a96caebbe3539e3744daaa1f1c1a5cf72d05
MD5 hash:
a7408cf2d8a68c9d621f04510d013c25
SHA1 hash:
06710b16a700b2f86ec7b77204b7d132a83a34f0
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.16
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.