🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 77457f0b7da19036041ca3a0071e141909d889eb7e2d28d6ad0df73bc3c81636. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 77457f0b7da19036041ca3a0071e141909d889eb7e2d28d6ad0df73bc3c81636
SHA3-384 hash: b61569db7377780c31c6362e6e9f36ab88720b128972097a10605728e9d767d68e7211951c878dce57b1259cf582921b
SHA1 hash: a322761d2f8eb898810454f545e8646495e98fea
MD5 hash: fbc2f28e187edcc6ddf89989ff8e591f
humanhash: eighteen-avocado-california-five
File name:readme
Download: download sample
Signature Gozi
File size:482'304 bytes
First seen:2022-03-23 09:47:57 UTC
Last seen:2022-03-23 11:54:41 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash e39598f41833b2ccc430630b77fddc6d (1 x Gozi)
ssdeep 12288:kwA6/9BSLnm6dO8YMKKFqPsfuqZOlas82Uoh:kpWsnRdOivIyZG8w
Threatray 543 similar samples on MalwareBazaar
TLSH T167A46D36E6E0C433D17637BCDD1BA6689C29BF506D68688A2BE81DCC4F3D7413529293
File icon (PE):PE icon
dhash icon 399998ecd4d46c0e (573 x Quakbot, 312 x GCleaner, 137 x ArkeiStealer)
Reporter JAMESWT_WT
Tags:dll exe Gozi isfb mite pw mite2022# Ursnif

Intelligence


File Origin
# of uploads :
2
# of downloads :
552
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
control.exe greyware keylogger
Gathering data
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2022-03-23 09:48:10 UTC
File Type:
PE (Dll)
Extracted files:
38
AV detection:
20 of 26 (76.92%)
Threat level:
  5/5
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:7627 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
vilogerta.top
linkspremium.ru
premiumlists.ru
Unpacked files
SH256 hash:
dfc1695accbc5b60d6ddec272d4dbe47cd37248172b748d9e17424cf0d311dd5
MD5 hash:
e62c8cd83c973803719f957aa5d7c7b4
SHA1 hash:
f86e4eb7601662afbdfc6f1d0fe58074340f95a0
Detections:
win_isfb_auto
SH256 hash:
4d34a7f79a78d18656167c38f4fb33d5e9a3e233e84a2238f2d0f6df208b52fa
MD5 hash:
d1a3c115a2cee09715572c7ee70451b1
SHA1 hash:
44d4963140af2515e2884b3e8077fed446e01438
Detections:
win_isfb_auto
SH256 hash:
77457f0b7da19036041ca3a0071e141909d889eb7e2d28d6ad0df73bc3c81636
MD5 hash:
fbc2f28e187edcc6ddf89989ff8e591f
SHA1 hash:
a322761d2f8eb898810454f545e8646495e98fea
Malware family:
CryptOne
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

DLL dll 77457f0b7da19036041ca3a0071e141909d889eb7e2d28d6ad0df73bc3c81636

(this sample)

Comments