MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ac6a11ecf700dafee430abe06d62b96a2180f08b1b83b7128e2b9bcab1d67959. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Gozi
Vendor detections: 10
| SHA256 hash: | ac6a11ecf700dafee430abe06d62b96a2180f08b1b83b7128e2b9bcab1d67959 |
|---|---|
| SHA3-384 hash: | 679d91e932e08425c6b61fe4759f147cb0d1d3a80c69bec2f57ebf67d92879dd2d774fbdd6a8e65ce58bb5ed263dff4e |
| SHA1 hash: | 1e07e548668918d5db3c7b907ad765f2996ff5c5 |
| MD5 hash: | 3b69cd2054a8234939a684ed60b7d671 |
| humanhash: | uranus-fifteen-uniform-princess |
| File name: | ac6a11ecf700dafee430abe06d62b96a2180f08b1b83b7128e2b9bcab1d67959 |
| Download: | download sample |
| Signature | Gozi |
| File size: | 723'301 bytes |
| First seen: | 2023-03-29 23:19:11 UTC |
| Last seen: | 2023-03-30 08:42:22 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | afb90fe87929848463a7c6f2fd59415c (1 x Gozi) |
| ssdeep | 3072:XGMvz842hp4xCCIaBCpGkWSkx0cf5P0UGwS+9BNmA6a:Xtx2yBCiSkxPNT7Ya |
| TLSH | T190F40EC482BF7D17DC215E3F456A01E073798497B78D4287D8C49939AB7D122AECE2AC |
| TrID | 41.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 26.1% (.EXE) Win64 Executable (generic) (10523/12/4) 12.5% (.EXE) Win16 NE executable (generic) (5038/12/1) 5.1% (.ICL) Windows Icons Library (generic) (2059/9) 5.0% (.EXE) OS/2 Executable (generic) (2029/13) |
| File icon (PE): | |
| dhash icon | 10b064ca969cc960 (1 x Gozi) |
| Reporter | Anonymous |
| Tags: | exe Gozi Ursnif |
Intelligence
File Origin
# of uploads :
3
# of downloads :
410
Origin country :
USVendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
ac6a11ecf700dafee430abe06d62b96a2180f08b1b83b7128e2b9bcab1d67959
Verdict:
No threats detected
Analysis date:
2023-03-29 23:19:52 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Result
Verdict:
Malware
Maliciousness:
Behaviour
Creating a window
Сreating synchronization primitives
DNS request
Sending a custom TCP request
Sending an HTTP GET request
Running batch commands
Launching a process
Creating a file in the %temp% directory
Launching the process to interact with network services
Result
Malware family:
n/a
Score:
8/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
MeasuringTime
EvasionQueryPerformanceCounter
EvasionGetTickCount
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
anti-debug gozi overlay spyeye
Verdict:
Suspicious
Labled as:
HVM:Trojan/W64.Emotet
Verdict:
Suspicious
Result
Threat name:
Bazar Loader, Ursnif
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Signature
Early bird code injection technique detected
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected Bazar Loader
Yara detected Ursnif
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Ursnif
Status:
Malicious
First seen:
2023-03-29 23:20:09 UTC
File Type:
PE+ (Dll)
Extracted files:
806
AV detection:
7 of 24 (29.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
gozi
Score:
10/10
Tags:
family:gozi botnet:1000 banker ldr4 trojan
Behaviour
Runs net.exe
Suspicious use of WriteProcessMemory
Program crash
Gozi
Malware Config
C2 Extraction:
https://ceredovza.top
Unpacked files
SH256 hash:
217bfc6e9f6e8a0aff773cd55510eea84deae5162ad7a97388d2a1fd081b1f33
MD5 hash:
2aada984311db7c34cd9cc3ceacca72e
SHA1 hash:
2b7286ac82463579418dc46d45528e37725d4ffd
SH256 hash:
ac6a11ecf700dafee430abe06d62b96a2180f08b1b83b7128e2b9bcab1d67959
MD5 hash:
3b69cd2054a8234939a684ed60b7d671
SHA1 hash:
1e07e548668918d5db3c7b907ad765f2996ff5c5
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.