🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4c7d46ab94add85adc74f9686c7367fd82eaae508b3e2227db8e62930fb3da0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: a4c7d46ab94add85adc74f9686c7367fd82eaae508b3e2227db8e62930fb3da0
SHA3-384 hash: b8fe13c89e5ce7c22527cfa581a9b5e50669d22ab93619b9a14dc281e2c5c0deec67b19cc97062e437b53adb946cf923
SHA1 hash: 9103735e9771b40fb26b5b273683934dfea38402
MD5 hash: 631779ef3aecb4838360304f162dbd8c
humanhash: lamp-robin-seven-helium
File name:beneficial.dll
Download: download sample
Signature Gozi
File size:658'944 bytes
First seen:2021-07-29 23:40:34 UTC
Last seen:2021-07-30 00:51:47 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 5423692ba88a3c92be390093c1045a0c (1 x Gozi)
ssdeep 12288:HMUpikM1ABVY4lsBnllWzwazxRvwe9QKC71L715+PoR5nFIlW2i:K4Y4lglQzwyxRvwySJLT5FIV
TLSH T1DEE47D10BA509835E1F362B54B6AA269631D35B12B2050CF72FC6EEE1FB45E27D3530B
Reporter Anonymous
Tags:dll Gozi

Intelligence


File Origin
# of uploads :
2
# of downloads :
251
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Compiles code for process injection (via .Net compiler)
Creates a thread in another existing process (thread injection)
Found malware configuration
Hooks registry keys query functions (used to hide registry keys)
Injects code into the Windows Explorer (explorer.exe)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Modifies the export address table of user mode modules (user mode EAT hooks)
Modifies the import address table of user mode modules (user mode IAT hooks)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: Encoded IEX
Sigma detected: MSHTA Spawning Windows Shell
Sigma detected: Suspicious Csc.exe Source File Folder
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Writes or reads registry keys via WMI
Writes registry values via WMI
Writes to foreign memory regions
Yara detected Ursnif
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 456598 Sample: beneficial.dll Startdate: 30/07/2021 Architecture: WINDOWS Score: 100 79 app.flashgameo.at 2->79 81 resolver1.opendns.com 2->81 89 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->89 91 Multi AV Scanner detection for domain / URL 2->91 93 Found malware configuration 2->93 95 11 other signatures 2->95 10 loaddll32.exe 1 2->10         started        14 mshta.exe 19 2->14         started        16 mshta.exe 2->16         started        signatures3 process4 dnsIp5 83 gtr.antoinfer.com 10->83 109 Writes to foreign memory regions 10->109 111 Allocates memory in foreign processes 10->111 113 Modifies the context of a thread in another process (thread injection) 10->113 117 3 other signatures 10->117 18 cmd.exe 1 10->18         started        20 rundll32.exe 10->20         started        23 control.exe 10->23         started        30 2 other processes 10->30 115 Suspicious powershell command line found 14->115 25 powershell.exe 1 32 14->25         started        28 powershell.exe 16->28         started        signatures6 process7 file8 32 rundll32.exe 2 18->32         started        97 System process connects to network (likely due to code injection or exploit) 20->97 99 Writes registry values via WMI 20->99 71 C:\Users\user\AppData\...\kdz1kgtq.cmdline, UTF-8 25->71 dropped 101 Injects code into the Windows Explorer (explorer.exe) 25->101 103 Writes to foreign memory regions 25->103 105 Compiles code for process injection (via .Net compiler) 25->105 36 csc.exe 25->36         started        39 csc.exe 25->39         started        41 conhost.exe 25->41         started        43 explorer.exe 25->43 injected 73 C:\Users\user\AppData\Local\...\y3j0hr41.0.cs, UTF-8 28->73 dropped 107 Creates a thread in another existing process (thread injection) 28->107 45 csc.exe 28->45         started        47 csc.exe 28->47         started        49 conhost.exe 28->49         started        signatures9 process10 dnsIp11 75 app.flashgameo.at 185.228.233.17, 49725, 49726, 49727 ITOS-ASRU Russian Federation 32->75 77 gtr.antoinfer.com 32->77 85 System process connects to network (likely due to code injection or exploit) 32->85 87 Writes to foreign memory regions 32->87 51 control.exe 32->51         started        63 C:\Users\user\AppData\Local\...\kdz1kgtq.dll, PE32 36->63 dropped 53 cvtres.exe 36->53         started        65 C:\Users\user\AppData\Local\...\tangn2aw.dll, PE32 39->65 dropped 55 cvtres.exe 39->55         started        67 C:\Users\user\AppData\Local\...\4mppu3lx.dll, PE32 45->67 dropped 57 cvtres.exe 45->57         started        69 C:\Users\user\AppData\Local\...\y3j0hr41.dll, PE32 47->69 dropped 59 cvtres.exe 47->59         started        file12 signatures13 process14 process15 61 rundll32.exe 51->61         started       
Threat name:
Win32.Trojan.BankerX
Status:
Malicious
First seen:
2021-07-29 23:41:04 UTC
AV detection:
6 of 28 (21.43%)
Threat level:
  5/5
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:1500 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
gtr.antoinfer.com
app.bighomegl.at
Unpacked files
SH256 hash:
a4c7d46ab94add85adc74f9686c7367fd82eaae508b3e2227db8e62930fb3da0
MD5 hash:
631779ef3aecb4838360304f162dbd8c
SHA1 hash:
9103735e9771b40fb26b5b273683934dfea38402
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments