MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6c23b59b8b2e93e87c942b800dbaf28bcc8b4cb7eb327b5af502cfa14b288dc9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 10
| SHA256 hash: | 6c23b59b8b2e93e87c942b800dbaf28bcc8b4cb7eb327b5af502cfa14b288dc9 |
|---|---|
| SHA3-384 hash: | 48abe441f635c5a7b26cf4036b56d67d7eddab54537d82cc9b5220c161b3020c1d4525a5b775e5ea81617b5e1bbd1459 |
| SHA1 hash: | c5cf5164b0d0d550e394053ab6a6a1b6ac0a0282 |
| MD5 hash: | d69286b5953690e11cc3a99d824dd551 |
| humanhash: | salami-mississippi-fillet-sad |
| File name: | ca1.dll |
| Download: | download sample |
| Signature | Gozi |
| File size: | 927'744 bytes |
| First seen: | 2022-01-06 10:53:56 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 5184ddf56390bae663e0b4d4e32ac3fc (1 x Gozi) |
| ssdeep | 12288:OrBi/7b5mPjBlsn8YMKNfCUeinhnXXea:fZmPjBa0KwUM |
| TLSH | T1F815FAA779E9FF49C8BB9434C1B0B365D2276C114A91890EC2DB3620BEB27EC1D45D1B |
| File icon (PE): | |
| dhash icon | 736934fc4de8cc92 (4 x Quakbot, 3 x Gozi, 1 x CryptBot) |
| Reporter | |
| Tags: | dll exe Gozi ZLoader |
Intelligence
File Origin
# of uploads :
1
# of downloads :
337
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
ca1.dll
Verdict:
No threats detected
Analysis date:
2022-01-06 11:00:30 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
Ursnif3
Detection(s):
Result
Verdict:
Clean
Maliciousness:
Behaviour
DNS request
Sending a custom TCP request
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
greyware
Malware family:
Ursnif
Verdict:
Malicious
Result
Threat name:
Ursnif
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Found malware configuration
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
PE file has nameless sections
Rundll32 performs DNS lookup (likely malicious behavior)
Sigma detected: Suspicious Call by Ordinal
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Sleltasos
Status:
Malicious
First seen:
2021-11-23 02:59:24 UTC
File Type:
PE (Dll)
Extracted files:
35
AV detection:
22 of 28 (78.57%)
Threat level:
5/5
Result
Malware family:
gozi_ifsb
Score:
10/10
Tags:
family:gozi_ifsb botnet:9093 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
http://google.mail.com
http://392184281.com
http://592182812.com
https://392184281.com
https://592182812.com
http://392184281.com
http://592182812.com
https://392184281.com
https://592182812.com
Unpacked files
SH256 hash:
e2b32f1118bca8547ec2d78a435cfefe58811b58cfd97b919676c4e517741fcc
MD5 hash:
5201123592d4413ad75dcace1575cf51
SHA1 hash:
c6ef08427279221f77d55df6ab54845a5af91a7d
Detections:
win_isfb_auto
SH256 hash:
76009702fec0d341e366ba33329fc5428c15a970dc77be21f3edafa2e130dda2
MD5 hash:
a9738a3f18c8b9608bb4defe80e83262
SHA1 hash:
a12a2dab1d13c53c1e71ce48e25f5f15b9a5f241
Detections:
win_isfb_auto
SH256 hash:
6c23b59b8b2e93e87c942b800dbaf28bcc8b4cb7eb327b5af502cfa14b288dc9
MD5 hash:
d69286b5953690e11cc3a99d824dd551
SHA1 hash:
c5cf5164b0d0d550e394053ab6a6a1b6ac0a0282
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.