🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35
SHA3-384 hash: 88f3c1325dd7f119f998663c1e36ef6856f1f5860f450891981ca4148c7c81c14a59b4b4a8813a549a51fba839c658c7
SHA1 hash: 64f3448fdba042bd2de11cbaffe0ddd8ab778903
MD5 hash: 7684a97f903ad72843cc1202b9700415
humanhash: victor-orange-august-uncle
File name:912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35.bin
Download: download sample
Signature Gozi
File size:3'023'360 bytes
First seen:2023-07-14 16:19:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d8cf501f2ead6a968abf3df1e5f5d366 (3 x Gozi, 2 x WikiLoader)
ssdeep 49152:vEFD9UfWifI29mfKQnMg2XgEl7MV/yTm:PU9yTm
Threatray 2 similar samples on MalwareBazaar
TLSH T1D1E5494562AD84E1E07B90BDD6DFBA1FF5213408071096CB06E44A9D6F33FE94BBA721
TrID 89.2% (.CPL) Windows Control Panel Item (generic) (197083/11/60)
4.7% (.EXE) Win64 Executable (generic) (10523/12/4)
2.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.9% (.ICL) Windows Icons Library (generic) (2059/9)
0.9% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter k3dg3___
Tags:exe Gozi Ursnif WikiLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
378
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
greyware masquerade
Verdict:
Malicious
Labled as:
Win64/Agent_AGeneric.AMY trojan
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2023-07-14 16:20:12 UTC
File Type:
PE+ (Dll)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35
MD5 hash:
7684a97f903ad72843cc1202b9700415
SHA1 hash:
64f3448fdba042bd2de11cbaffe0ddd8ab778903
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Gozi

Executable exe 912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35

(this sample)

Comments