MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7aa84b4ce4fbf937632d3008981c3ef8ff63e1ff846fdbb55060f3973d2507a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7aa84b4ce4fbf937632d3008981c3ef8ff63e1ff846fdbb55060f3973d2507a9
SHA3-384 hash: 4cd89583a22adaab30514d004d5f5e09dbd448578e96389e0b1772acea77ae95b6066236d759a93bd01038fe101a9f45
SHA1 hash: c1bff59350a7117762e34817f2a0f2edbdec11bf
MD5 hash: a7cbf4937c36b65d7af6aeb54e8b63f0
humanhash: alpha-don-april-twelve
File name:7aa84b4ce4fbf937632d3008981c3ef8ff63e1ff846fdbb55060f3973d2507a9
Download: download sample
Signature Gozi
File size:258'560 bytes
First seen:2020-03-23 18:47:06 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e2d0e126f7a19f70045cfe55b9d70336 (1 x Gozi)
ssdeep 3072:K8ryRp0lYf9fOeJsJaNFJS55tood+FgD8GvNweh+u9qh+xBNyBN5k2XDaQsecHtI:KkRlQJsMFsvtjZhnqhyUrDB+NvQ
Threatray 552 similar samples on MalwareBazaar
TLSH 1544BF0176D2C432E7B3017389AD9A2542FEBD720B3499C777880A4DED712E17E3A676
Reporter Marco_Ramilli
Tags:exe Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2019-07-22 17:45:01 UTC
File Type:
PE (Exe)
Extracted files:
17
AV detection:
26 of 30 (86.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

Executable exe 7aa84b4ce4fbf937632d3008981c3ef8ff63e1ff846fdbb55060f3973d2507a9

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WINHTTP.dll::WinHttpCloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::PeekConsoleInputW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetConsoleCursorPosition
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
WIN_HTTP_APIUses HTTP servicesWINHTTP.dll::WinHttpOpen
WINHTTP.dll::WinHttpOpenRequest
WINHTTP.dll::WinHttpQueryHeaders
WINHTTP.dll::WinHttpReadData
WINHTTP.dll::WinHttpSendRequest
WIN_USER_APIPerforms GUI ActionsUSER32.dll::PeekMessageA

Comments