🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88adde1c67af1d13fbcfadc97833449e884d24ac0bf13fd47c8284a6611532db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 88adde1c67af1d13fbcfadc97833449e884d24ac0bf13fd47c8284a6611532db
SHA3-384 hash: 3fe8b69547824191b167ce971c8dabaf35bee7d6498561a78bb24ecfebfc576e46b684cd80dc95fa6ab5a0a4dc5c348e
SHA1 hash: cc79069a10cfc4aff0a769695e878bc8b1c2344c
MD5 hash: b79471183dafff2c64bd5c9c737c0ea9
humanhash: carolina-september-helium-failed
File name:2nd-stage.dll
Download: download sample
Signature Gozi
File size:111'104 bytes
First seen:2023-01-31 10:10:41 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash fd0e2ccb5477f66b73c01659efb44b9e (1 x Gozi)
ssdeep 3072:MklTvLbBVJeAOwzku8ymvr1QzkwsAWvVaUD:NTvxveAF8ym5QHsAcVV
TLSH T1F7B3AE55B996C170E0C09E7628396637FD3F9D7D5B60823B6FD7E6E48DF2011CA0A282
TrID 33.2% (.EXE) Win32 Executable (generic) (4505/5/1)
22.1% (.MZP) WinArchiver Mountable compressed Archive (3000/1)
14.9% (.EXE) OS/2 Executable (generic) (2029/13)
14.7% (.EXE) Generic Win/DOS Executable (2002/3)
14.7% (.EXE) DOS Executable Generic (2000/1)
Reporter JAMESWT_WT
Tags:2nd-stage agenziaentrate dll Gozi Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
224
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Using the Windows Management Instrumentation requests
DNS request
Sending an HTTP GET request
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
greyware packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking system information)
Found stalling execution ending in API Sleep call
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 795043 Sample: 2nd-stage.dll Startdate: 31/01/2023 Architecture: WINDOWS Score: 100 32 Snort IDS alert for network traffic 2->32 34 Malicious sample detected (through community Yara rule) 2->34 36 Multi AV Scanner detection for submitted file 2->36 38 Yara detected  Ursnif 2->38 8 loaddll32.exe 7 2->8         started        process3 signatures4 48 Found evasive API chain (may stop execution after checking system information) 8->48 50 Found API chain indicative of debugger detection 8->50 52 Writes or reads registry keys via WMI 8->52 54 Writes registry values via WMI 8->54 11 cmd.exe 1 8->11         started        13 regsvr32.exe 6 8->13         started        16 rundll32.exe 6 8->16         started        18 3 other processes 8->18 process5 signatures6 20 rundll32.exe 6 11->20         started        56 Writes or reads registry keys via WMI 13->56 58 Writes registry values via WMI 13->58 60 System process connects to network (likely due to code injection or exploit) 16->60 24 WerFault.exe 24 9 18->24         started        process7 dnsIp8 28 91.215.85.193, 49709, 49711, 49712 PINDC-ASRU Russian Federation 20->28 40 Found evasive API chain (may stop execution after checking system information) 20->40 42 Found stalling execution ending in API Sleep call 20->42 44 Found API chain indicative of debugger detection 20->44 46 Writes registry values via WMI 20->46 30 192.168.2.1 unknown unknown 24->30 26 conhost.exe 24->26         started        signatures9 process10
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2023-01-31 10:11:05 UTC
File Type:
PE (Dll)
AV detection:
15 of 26 (57.69%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi
Malware Config
C2 Extraction:
config.edge.skype.com
91.215.85.193
Unpacked files
SH256 hash:
6bf235ea664a1d5d0bd61d4873be33ebf6bd7588472678f53345d24625b51fad
MD5 hash:
f99a5f0bbd7aa03cd9a9dc0b718348b5
SHA1 hash:
f78d2ac746958e14a6e8a9217669c7ddd5bd9691
SH256 hash:
879f623b5f46d7fab80dbdbca433ff90e2de0ed40e52e90b22593406d4e58a51
MD5 hash:
173626e3bea1fc090c2f01bbee765270
SHA1 hash:
c6a221ccbb897dd5fbf62e1b5f50a7448794bfeb
SH256 hash:
88adde1c67af1d13fbcfadc97833449e884d24ac0bf13fd47c8284a6611532db
MD5 hash:
b79471183dafff2c64bd5c9c737c0ea9
SHA1 hash:
cc79069a10cfc4aff0a769695e878bc8b1c2344c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments