🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8282218eddaf268ea97b6ecea9ae51a52ce6fa063c198c5e5ef02ec95f23c7bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 10


Intelligence 10 IOCs YARA 1 File information Comments

SHA256 hash: 8282218eddaf268ea97b6ecea9ae51a52ce6fa063c198c5e5ef02ec95f23c7bf
SHA3-384 hash: 85ef15829e6bfd57dea9d6bd2329bd3099f9dfc7b83b56a1fdcb25b50fc3d8c811abeb40fd6362da652b396adff956c7
SHA1 hash: 3ab34ca8c5aa1792212fd956118db367d3ea1adc
MD5 hash: 3283203daaa2e26233f7fa099fb823b0
humanhash: lake-maine-september-fourteen
File name:app.dll
Download: download sample
Signature Gozi
File size:1'028'096 bytes
First seen:2021-06-15 17:17:09 UTC
Last seen:2021-06-16 10:56:48 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 5631b8b671d77777e9f81d7224f501a1 (1 x Gozi)
ssdeep 12288:HjyaZO+bee+T5uQ63I55CTqZN+a+6tVhbYTzGC3evhTrP0MGsz0:Dy8O+qeU5unPTqHbYuOevhP8M3Q
Threatray 383 similar samples on MalwareBazaar
TLSH DC258D01BA11F024E5AA01F44F6DD79DAB1C3EA19B5422CB73E56EDF6E6D1E3A430309
Reporter info_sec_ca
Tags:dll Gozi

Intelligence


File Origin
# of uploads :
2
# of downloads :
206
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file
Sending a UDP request
Using the Windows Management Instrumentation requests
Launching a process
Creating a window
DNS request
Sending an HTTP GET request
Searching for the window
Deleting a recently created file
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Found malware configuration
Multi AV Scanner detection for domain / URL
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 434998 Sample: app.dll Startdate: 15/06/2021 Architecture: WINDOWS Score: 68 27 Multi AV Scanner detection for domain / URL 2->27 29 Found malware configuration 2->29 31 Yara detected  Ursnif 2->31 7 loaddll32.exe 1 2->7         started        9 iexplore.exe 2 60 2->9         started        process3 process4 11 rundll32.exe 7->11         started        14 cmd.exe 1 7->14         started        16 rundll32.exe 7->16         started        21 3 other processes 7->21 18 iexplore.exe 39 9->18         started        dnsIp5 33 Writes registry values via WMI 11->33 23 rundll32.exe 14->23         started        25 authd.feronok.com 185.233.80.31, 49733, 49734, 80 SUPERSERVERSDATACENTERRU Russian Federation 18->25 signatures6 process7
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2021-06-15 17:18:20 UTC
AV detection:
7 of 29 (24.14%)
Threat level:
  5/5
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:1500 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
authd.feronok.com
app.bighomegl.at
Unpacked files
SH256 hash:
14bb42218bc0ef258cdb7792388bf134ec0a87ebdff3494283a063091284fd97
MD5 hash:
82c485cecd9fac6538b00d3e7a0308e0
SHA1 hash:
4d518fa6ae20b226f942ba79c9f51c4e80bab142
Detections:
win_isfb_auto
SH256 hash:
10e449e5a4f442b7c4f35111bc08ffd7de8625ca3a8174cc930dc33a3bd850d6
MD5 hash:
c85391796289cf7c54375de78720560c
SHA1 hash:
626513ce3302bfa4995b631190b8928ec506534f
Detections:
win_isfb_auto
SH256 hash:
8282218eddaf268ea97b6ecea9ae51a52ce6fa063c198c5e5ef02ec95f23c7bf
MD5 hash:
3283203daaa2e26233f7fa099fb823b0
SHA1 hash:
3ab34ca8c5aa1792212fd956118db367d3ea1adc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

DLL dll 8282218eddaf268ea97b6ecea9ae51a52ce6fa063c198c5e5ef02ec95f23c7bf

(this sample)

  
Delivery method
Distributed via web download

Comments