🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e7132b7f209c5d7ca450c8f3440ca373de14fee0fe993e97cfd7caa21316af3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 8e7132b7f209c5d7ca450c8f3440ca373de14fee0fe993e97cfd7caa21316af3
SHA3-384 hash: 8501035227ad1b0ec938423ac1b587cde14e40f31b7a4a1db9faea6f1c17bce04ca9a12b7add4003087c97427bd31083
SHA1 hash: 1aefcbc0c6935227d01b7af2d99e53b193a6cb3b
MD5 hash: 256243501cc798f14327bed5057d0c4f
humanhash: moon-maryland-triple-thirteen
File name:iX27GQW.zip
Download: download sample
Signature Gozi
File size:388'885 bytes
First seen:2023-10-13 10:42:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:gD4PgvBaX7MupMkOje8YXVUXsADE4QgHMe/d8DYGbgYNWgmOv1b6/u/P:gD4PgG7MenhXCXsQrDu7bDNWgmO92e
TLSH T1478423B17B1BCC61EA95CC74515FDAB14A51BF08536FA27A1A5EAD2CDC180924C2CF0F
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:Gozi qusbec-com sideloading zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
190
Origin country :
IT IT
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:thumbs.db
File size:18'566 bytes
SHA256 hash: a7c697235e45629e329ad28d0d8cb2c2a014a6ce55d20f92c6a992fc0c0f1c8f
MD5 hash: 73795f1209ce011c8e58e690ec093576
MIME type:application/octet-stream
Signature Gozi
File name:vs5.exe
File size:832'512 bytes
SHA256 hash: 105099819555ed87ef3dab70a2eaf2cb61076f453266cec57ffccb8f4c00df88
MD5 hash: 331a40eabaa5870e316b401bd81c4861
MIME type:application/x-dosexec
Signature Gozi
File name:xpspushlayer.dll
File size:31'496 bytes
SHA256 hash: 2e7251af64675b22c9d3a76fd8f1360593a5968f244ac707a8303b3dd9da502e
MD5 hash: 023465ce4787e0b333d26e899b275bb8
MIME type:application/x-dosexec
Signature Gozi
File name:5vJcHz7g.dll
File size:31'496 bytes
SHA256 hash: 09b5a80fdf4e4a9dd17220e188aa7761ce6e04a43eb349237acb1456b684847a
MD5 hash: b1f216ed5e0129e65b7d57d76f64dafc
MIME type:application/x-dosexec
Signature Gozi
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
89%
Tags:
overlay packed
Threat name:
Win64.Trojan.Ulise
Status:
Malicious
First seen:
2023-10-13 10:43:04 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments