🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 beb762d325c6c8ae3cb3876c6491913a51a2a79f336bf0509641e1ad9bddbaec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: beb762d325c6c8ae3cb3876c6491913a51a2a79f336bf0509641e1ad9bddbaec
SHA3-384 hash: 4506aab036c14ae7189dc4e870e9897cd98f9f76a003660597211d1ce46265d0c3fe9a4ed85daab0d1ecb5d025b59106
SHA1 hash: 9c55a13226a3b898a594138fd63aba358ea41732
MD5 hash: 44b4b391d4fafd15bf4f384abec244fa
humanhash: eleven-edward-diet-minnesota
File name:documents-998725151.zip
Download: download sample
Signature Gozi
File size:421'139 bytes
First seen:2023-03-02 19:58:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:C2zKUlggYedmoWXlXIEUYm0G7TniW+rv042uxdi:C0ggVm9BBUhriB8Q2
TLSH T1629423F594BA6D94D3811E628E03F844F5A30D6935E07F8DBC933A3C69A6C210E6F91D
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter k3dg3___
Tags:20000 Gozi ta579 Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:documents7.exe
File size:466'944 bytes
SHA256 hash: a240d325f163f4dd9e3ea176d85a1f0864b31efe774402f3cd03c27ea15a4ae1
MD5 hash: a86a8857981e84a0920f7e6e793c7f33
MIME type:application/x-dosexec
Signature Gozi
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed setupapi.dll
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:20000 banker isfb trojan
Behaviour
Gozi
Malware Config
C2 Extraction:
https://checklistg.google.com
http://185.189.151.250
https://edge14.microsoft.com
http://45.11.181.117
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropping
a240d325f163f4dd9e3ea176d85a1f0864b31efe774402f3cd03c27ea15a4ae1
  
Delivery method
Distributed via e-mail link

Comments