🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3b6be96582dc92249e78db51d0abe50e78b623f9bcc09405b587d736d6dc451. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 15


Intelligence 15 IOCs YARA File information Comments

SHA256 hash: c3b6be96582dc92249e78db51d0abe50e78b623f9bcc09405b587d736d6dc451
SHA3-384 hash: 4ceab7b37a449e9d5af2060ed3b8d00e17421562a7840953f81acb2b4e7a8eee36bd2dc697f95e4c607b2da9b896b742
SHA1 hash: 261adac029e864d5480468313319539f3dbd951a
MD5 hash: 28a6df75f54f6b40ff2b7b2920001bcb
humanhash: seventeen-kansas-dakota-neptune
File name:atw3.dll
Download: download sample
Signature Gozi
File size:467'968 bytes
First seen:2024-12-26 23:53:19 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 067c9eaf965ff911e0d45a66ba273628 (1 x Gozi)
ssdeep 12288:s0/eyQTPl2tZrqu9MxbrWDRt3SaLPIEfG28wK6t:s0/8sbj6W91SgYJwK
TLSH T157A4235BDDB0CF1BE392AC35CCB44AA7591FDA14E6B0E8F7A3071A5C84154BD230946E
TrID 28.5% (.EXE) Win64 Executable (generic) (10522/11/4)
17.8% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
13.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
12.2% (.EXE) Win32 Executable (generic) (4504/4/1)
5.6% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
Reporter k0ng0x
Tags:dll Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
548
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Searching for synchronization primitives
Launching a process
DNS request
Connection attempt
Sending an HTTP GET request
Sending a custom TCP request
Creating a window
Changing a file
Setting browser functions hooks
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Unauthorized injection to a browser process
Result
Threat name:
Gozi, Ursnif
Detection:
malicious
Classification:
phis.bank.troj.spyw.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes memory attributes in foreign processes to executable or writable
Contain functionality to detect virtual machines
Contains functionality to compare user and computer (likely to detect sandboxes)
Creates a thread in another existing process (thread injection)
Detected Gozi e-Banking trojan
Disables SPDY (HTTP compression, likely to perform web injects)
Found malware configuration
Found PHP interpreter
Found Tor onion address
Hooks registry keys query functions (used to hide registry keys)
Injects code into the Windows Explorer (explorer.exe)
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Modifies the export address table of user mode modules (user mode EAT hooks)
Modifies the import address table of user mode modules (user mode IAT hooks)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites Mozilla Firefox settings
PE file has a writeable .text section
Sigma detected: Suspect Svchost Activity
Switches to a custom stack to bypass stack traces
System process connects to network (likely due to code injection or exploit)
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to harvest and steal browser information (history, passwords, etc)
Writes to foreign memory regions
Yara detected Ursnif
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581113 Sample: atw3.dll Startdate: 27/12/2024 Architecture: WINDOWS Score: 100 52 ardshinbank.at 2->52 54 www.php.net 2->54 56 5 other IPs or domains 2->56 60 Found malware configuration 2->60 62 Malicious sample detected (through community Yara rule) 2->62 64 Antivirus detection for dropped file 2->64 66 13 other signatures 2->66 10 loaddll32.exe 3 2->10         started        signatures3 process4 signatures5 92 Detected Gozi e-Banking trojan 10->92 94 Contain functionality to detect virtual machines 10->94 96 Writes to foreign memory regions 10->96 98 5 other signatures 10->98 13 regsvr32.exe 1 2 10->13         started        16 cmd.exe 1 10->16         started        18 rundll32.exe 2 10->18         started        20 2 other processes 10->20 process6 signatures7 100 Detected Gozi e-Banking trojan 13->100 102 Contain functionality to detect virtual machines 13->102 104 Writes to foreign memory regions 13->104 120 2 other signatures 13->120 22 svchost.exe 1 13->22         started        25 rundll32.exe 1 3 16->25         started        106 Allocates memory in foreign processes 18->106 108 Modifies the context of a thread in another process (thread injection) 18->108 110 Maps a DLL or memory area into another process 18->110 28 svchost.exe 18->28         started        112 Found PHP interpreter 20->112 114 Found Tor onion address 20->114 116 Injects code into the Windows Explorer (explorer.exe) 20->116 118 Creates a thread in another existing process (thread injection) 20->118 process8 file9 68 Detected Gozi e-Banking trojan 22->68 70 Found PHP interpreter 22->70 72 Found Tor onion address 22->72 74 Maps a DLL or memory area into another process 22->74 30 explorer.exe 10 1 22->30 injected 48 C:\Users\user\AppData\...\adsnrans.dll, PE32 25->48 dropped 76 Writes to foreign memory regions 25->76 78 Allocates memory in foreign processes 25->78 80 Modifies the context of a thread in another process (thread injection) 25->80 82 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 25->82 34 svchost.exe 1 25->34         started        37 conhost.exe 25->37         started        84 Injects code into the Windows Explorer (explorer.exe) 28->84 86 Creates a thread in another existing process (thread injection) 28->86 signatures10 process11 dnsIp12 50 C:\Users\user\AppData\Roaming\...\prefs.js, ASCII 30->50 dropped 122 Detected Gozi e-Banking trojan 30->122 124 System process connects to network (likely due to code injection or exploit) 30->124 126 Found PHP interpreter 30->126 134 9 other signatures 30->134 39 rundll32.exe 30->39         started        42 RuntimeBroker.exe 30->42 injected 44 RuntimeBroker.exe 30->44 injected 46 2 other processes 30->46 58 www-php-net.ax4z.com 185.85.0.29, 443, 49730, 49731 SOPRADO-ANYDE Germany 34->58 128 Found Tor onion address 34->128 130 Injects code into the Windows Explorer (explorer.exe) 34->130 132 Writes to foreign memory regions 34->132 file13 signatures14 process15 signatures16 88 Found PHP interpreter 39->88 90 Found Tor onion address 39->90
Threat name:
Win32.Trojan.Ditertag
Status:
Malicious
First seen:
2017-06-15 18:23:32 UTC
File Type:
PE (Dll)
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
Score:
  10/10
Tags:
family:gozi banker discovery isfb trojan
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Gozi
Gozi family
Unpacked files
SH256 hash:
df83b13d57b4668a39d5ce520d0f003487490c8ad121687c851e20892e537d0e
MD5 hash:
75b9bc8b0f9a93613596ca5190bd9c4b
SHA1 hash:
9a07cebfa531b11085dcd5e5ad3c82e3215d8b78
Detections:
ISFB_Main
SH256 hash:
a3db10de78f96e8917208dcb581277b1465eb63d0294c331dc7e840729bc59c4
MD5 hash:
1a426e8500464e187064b1b3ad74a74d
SHA1 hash:
2347733e9913b01192e09c83f665b3b15a55619d
Detections:
ISFB_Main win_isfb_a5 win_dreambot_auto
SH256 hash:
0cc4905795813e68dcf8c65a33b4054d57b3027634e342546c701222cd656002
MD5 hash:
439942cf2615c407448eb20facef2c04
SHA1 hash:
e5bab5f2119164219d95828aa6a7d7a665c0b053
Detections:
ISFB_Main win_isfb_a5 win_dreambot_auto
SH256 hash:
c3b6be96582dc92249e78db51d0abe50e78b623f9bcc09405b587d736d6dc451
MD5 hash:
28a6df75f54f6b40ff2b7b2920001bcb
SHA1 hash:
261adac029e864d5480468313319539f3dbd951a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::GetNamedSecurityInfoA
ADVAPI32.dll::GetInheritanceSourceA
RPC_APICan Execute Remote ProceduresRPCRT4.dll::MesHandleFree
RPCRT4.dll::RpcBindingInqAuthClientExA
RPCRT4.dll::RpcObjectSetInqFn
RPCRT4.dll::RpcServerUseAllProtseqs
RPCRT4.dll::RpcServerUseProtseqEpA
WIN_BASE_APIUses Win Base APIKERNEL32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA
KERNEL32.dll::GetWindowsDirectoryA
KERNEL32.dll::GetWindowsDirectoryW
KERNEL32.dll::GetFileAttributesW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyW
ADVAPI32.dll::RegSaveKeyA

Comments