🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a950b61314bf165eacb7da3811d5a7dd3536d95b464d259c62ffe936c5ed720c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: a950b61314bf165eacb7da3811d5a7dd3536d95b464d259c62ffe936c5ed720c
SHA3-384 hash: 31c51b0e6c75ac994082d3615303dba21d68ff62e29f779437d141f9343c1265c0ccbfa75020f826e128a36f7c300683
SHA1 hash: 84b95c98cf8f738071066dd4e990996150609197
MD5 hash: 3ccb15fd85294f573f74350fc7770b81
humanhash: salami-five-diet-berlin
File name:foto.zip
Download: download sample
Signature Gozi
File size:148'897 bytes
First seen:2023-09-18 12:09:47 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:KV6rYkjbfgkqN1TP90PeAGnGC4EN/kMtmy2c9Pv70zp226y:S6fIyPeAWlkxq70zpd6y
TLSH T160E3133E0E5E8735A00DC6F54534DFB93A7844159C4329C8AB23A3D7646DF8DB8A21B8
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:62-173-145-113 Gozi SMB Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:portfolio.exe
File size:220'672 bytes
SHA256 hash: 573ecacb1ccfd4965e899ed3bb811181bf78b62399e10a5690491eb199e0291c
MD5 hash: f7a4f0c3ab59531900a3981d820712c8
MIME type:application/x-dosexec
Signature Gozi
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
greyware packed
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2023-09-18 12:09:20 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Gozi
Malware Config
C2 Extraction:
https://avas1ta.com/in/login/
192.121.22.216
http://mimemoa.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments