MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 5
| SHA256 hash: | 912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35 |
|---|---|
| SHA3-384 hash: | 88f3c1325dd7f119f998663c1e36ef6856f1f5860f450891981ca4148c7c81c14a59b4b4a8813a549a51fba839c658c7 |
| SHA1 hash: | 64f3448fdba042bd2de11cbaffe0ddd8ab778903 |
| MD5 hash: | 7684a97f903ad72843cc1202b9700415 |
| humanhash: | victor-orange-august-uncle |
| File name: | 912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35.bin |
| Download: | download sample |
| Signature | Gozi |
| File size: | 3'023'360 bytes |
| First seen: | 2023-07-14 16:19:20 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | d8cf501f2ead6a968abf3df1e5f5d366 (3 x Gozi, 2 x WikiLoader) |
| ssdeep | 49152:vEFD9UfWifI29mfKQnMg2XgEl7MV/yTm:PU9yTm |
| Threatray | 2 similar samples on MalwareBazaar |
| TLSH | T1D1E5494562AD84E1E07B90BDD6DFBA1FF5213408071096CB06E44A9D6F33FE94BBA721 |
| TrID | 89.2% (.CPL) Windows Control Panel Item (generic) (197083/11/60) 4.7% (.EXE) Win64 Executable (generic) (10523/12/4) 2.2% (.EXE) Win16 NE executable (generic) (5038/12/1) 0.9% (.ICL) Windows Icons Library (generic) (2059/9) 0.9% (.EXE) OS/2 Executable (generic) (2029/13) |
| Reporter | |
| Tags: | exe Gozi Ursnif WikiLoader |
Intelligence
File Origin
# of uploads :
1
# of downloads :
378
Origin country :
USVendor Threat Intelligence
Detection:
n/a
Result
Verdict:
Clean
Maliciousness:
Behaviour
Searching for the window
Verdict:
No Threat
Threat level:
2/10
Confidence:
100%
Tags:
greyware masquerade
Verdict:
Malicious
Labled as:
Win64/Agent_AGeneric.AMY trojan
Verdict:
Unknown
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2023-07-14 16:20:12 UTC
File Type:
PE+ (Dll)
AV detection:
7 of 24 (29.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
unknown
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
912cc2a3592b3b7835205d275cbf92bb66effc99cbd5cc338a223888de1b0d35
MD5 hash:
7684a97f903ad72843cc1202b9700415
SHA1 hash:
64f3448fdba042bd2de11cbaffe0ddd8ab778903
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.