🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8aaa6ad14089cb6cf30983ded8a0f00388fbdccd1f511fe06093b2241ebc5ded. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 8aaa6ad14089cb6cf30983ded8a0f00388fbdccd1f511fe06093b2241ebc5ded
SHA3-384 hash: 8bede9adcf948dc349573f54856d938e4043c3ab994e24ba4cdedf414e707da17fe7475bab27c0f94c5bca8bdca58c7d
SHA1 hash: 90bf2a7ef061ee0e5dc7c361b793cbce72146601
MD5 hash: e91efe32d1ba7af0e42c8d51f67b6934
humanhash: william-connecticut-stairway-lemon
File name:agenzia_delle_entrate.zip
Download: download sample
Signature Gozi
File size:40'779 bytes
First seen:2023-01-05 09:45:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:K/2swZnZsB77hYdwZ6LhF7zPDqvt/7CxsJdMtDLa+jRPOgEI5m7ZSGUG:K/pw7slhdUhFPDqV/0Z5La2POPSGr
TLSH T14203029CC2388676E5BEA5BED3A743398015F4ED27E224B26614BF19A384DBC9004E59
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter RaileanuIonut
Tags:Gozi zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
RO RO
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:agenzia_delle_entrate.url
File size:194 bytes
SHA256 hash: d1d80208de45d907fd3a8fab28bef80b917a96ee57784bcae2cd440838e26ebd
MD5 hash: c0068547cbde15fe13b58ecb576c4bf7
MIME type:text/plain
Signature Gozi
File name:Logo_Agenzia_Entrate.jpg
File size:41'005 bytes
SHA256 hash: 04e70f09ebfbf1da237fc196694116b7d74e4ddd5d81dac88c06ff7cb0228554
MD5 hash: 38b1898544f518dc7baafd1515b5842c
MIME type:image/jpeg
Signature Gozi
Vendor Threat Intelligence
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:7701 banker isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Gozi
Malware Config
C2 Extraction:
checklist.skype.com
62.173.145.223
31.41.44.105
45.89.66.58
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Methodology_Suspicious_Shortcut_SMB_URL
Author:@itsreallynick (Nick Carr), @QW5kcmV3 (Andrew Thompson)
Description:Detects remote SMB path for .URL persistence
Reference:https://twitter.com/cglyer/status/1176184798248919044

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments