🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd9eb63197dc09605156ce65dece7c6666490834928e39ed60118dbcd37ea414. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 6


Intelligence 6 IOCs YARA 8 File information Comments

SHA256 hash: cd9eb63197dc09605156ce65dece7c6666490834928e39ed60118dbcd37ea414
SHA3-384 hash: c22a1079c2467d2a715c482ea834d6db10f0bdd345b0a9dcb836e8bc934fe6d97bf21d455165e66a983760798c4d2252
SHA1 hash: afc18222b74085ff2bac6ebb7cb21c2903c9f9c2
MD5 hash: db23a7989912c8eb82ed0247ce0a1f85
humanhash: winner-oranges-tennessee-high
File name:foto.zip
Download: download sample
Signature Gozi
File size:148'348 bytes
First seen:2023-09-18 11:26:57 UTC
Last seen:2023-09-18 11:27:09 UTC
File type: zip
MIME type:application/zip
ssdeep 3072:E2JknmX20uQYYwkaaESKf3aIVm5SGfipnjPaXii+fUCA4zJ6p:EDmX20u4ql3zk9qpnjqAMCAhp
TLSH T10FE3128DFE8F655139013B0EDBDA1269E7D4B2EAA10673A383313DCE45C310ADA91D67
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:62-173-145-113 Gozi SMB Ursnif zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
132
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:portfolio.exe
File size:220'160 bytes
SHA256 hash: 326ad767ee63a1d88df314fc691c55cbf3e5b90985d858a649ccede0661f584d
MD5 hash: 116d417e8166f9b98b3e24fa7dc29379
MIME type:application/x-dosexec
Signature Gozi
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
greyware packed
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:5050 banker isfb trojan
Behaviour
Gozi
Malware Config
C2 Extraction:
https://avas1ta.com/in/login/
192.121.22.216
http://mimemoa.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_indirect_function_call_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Trojan_Smokeloader_3687686f
Author:Elastic Security
Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments