🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a238b91d64df210263f7f4b9bb0e60613bc29fa13f680a7e2b25b8c87769545. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9a238b91d64df210263f7f4b9bb0e60613bc29fa13f680a7e2b25b8c87769545
SHA3-384 hash: 6d8c2d174d44644e827d43ff693962f92c5e75327aa9e8c6829ed7b6d12969698f41da59e0dc5741957b4f1f6c42f5f1
SHA1 hash: ea6110262a7aa6730276569c359f4ba110bfdc47
MD5 hash: a6bf1b3f30119f708a142910e164e4d9
humanhash: ten-undress-sad-oranges
File name:Generale_Informazione.zip
Download: download sample
Signature Gozi
File size:918'368 bytes
First seen:2023-01-18 09:31:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:1MdrZnpm3hxcvEyMrfDkC7oukdyLq6B/ta7SttGWPLvmtVOvnT7Lu5KH7iSpdpX8:SnpmRrQC0ukiBpb/PLvmDynTuqxjq
TLSH T19015CEAC74B5FA5AF5D443BFC6852CF6CB2CA140D7993DCB8E2040567D8310E5F6A8A2
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:700AE agenziaentrate file-pumped Gozi zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Generale_Informazione.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:710'740'736 bytes
SHA256 hash: 5b6fc7a8245a33aff3be1fa8c7021219b8e14f938861c5bf5f2a40477aaf4566
MD5 hash: 9fe040847257df44a20608196fec06d2
De-pumped file size:724'992 bytes (Vs. original size of 710'740'736 bytes)
De-pumped SHA256 hash: 4fddc495d84c3b30397b2e3de7cdad79d322de9df03fa00bf792f6106a06a06f
De-pumped MD5 hash: 4eeb4ef9baa950b337e128ea45f2a902
MIME type:application/x-dosexec
Signature Gozi
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Dropper.Lazy
Status:
Malicious
First seen:
2023-01-18 10:15:55 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:7706 banker isfb persistence trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Gozi
Malware Config
C2 Extraction:
checklist.skype.com
62.173.147.43
31.41.44.157
193.233.175.98
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments