🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce412cd3202e853b57d0756427ee57e2477b1d8d9e694fd3f7dac8fcd3d05009. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments 1

SHA256 hash: ce412cd3202e853b57d0756427ee57e2477b1d8d9e694fd3f7dac8fcd3d05009
SHA3-384 hash: 2e64bdcea66629573bce3c7fb4940e1610af9848c82bec4739616ca58c0ac3ed0afe34c6f564592b2a700b0b5c7a5c84
SHA1 hash: 20cae8639e216e701fb2efa1aa2d378bbf904cf6
MD5 hash: 23cd6b7118d5333156a6d18306bae407
humanhash: saturn-vegan-sink-fifteen
File name:index.php
Download: download sample
Signature Gozi
File size:203 bytes
First seen:2024-03-15 13:19:29 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3:SnfM6J0+9AwLXHPtwrWFFdAFEeIAYRmT/EjGdg5KLnYeNMeFk9eOD6L4A76f5XmC:efQ+iWmFvGwTssWoo9e06kHf5mXyn
TLSH T170D0A9125A04BEBC84941B4ACB1B8848A12344E65A02EA2012CC88CAAC238895BACD69
Reporter MalwareMorghulis
Tags:bazaarbackdoor BazaarLoader powershell ps1


Avatar
MalwareMorghulis
Stage 1 payload called "index.php" was actually a PowerShell script to pull additional binaries down to the target system from various C2 domains. Attack binary Stage 2 was called "main.php" and was the actually executable. Upon execution the attack binary at Stage 2 would attempt to check for debuggers for anti-analysis and attempt to unpack itself in a separate area of memory. Stage 2 also dropped a DLL file called Soon.dll. IEV was an email containing a Google APIs link.

Stage-1
md5,23CD6B7118D5333156A6D18306BAE407,index.php
sha1,20CAE8639E216E701FB2EFA1AA2D378BBF904CF6,index.php
sha256,CE412CD3202E853B57D0756427EE57E2477B1D8D9E694FD3F7DAC8FCD3D05009,index.php

Stage-2
md5,7E9449A1E238D8CAAF39B5E911D71B21,main.php
sha1,1B5E7AA02340D85B14AF3DDDF7C86C2F7502BF50,main.php
sha256,B54DC5193824EB35233C3922687A5ADC462AB474362DD4EFFD488C2AE0DAE301,main.php

Stage-2 Execution
C:\Users\USERNAME\AppData\Local\Temp\leUafP.dat
c:\baby\high\ease\gener\side \soon.pdb

Intelligence


File Origin
# of uploads :
1
# of downloads :
288
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade powershell
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
80 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Sigma detected: Execute DLL with spoofed extension
Sigma detected: Potentially Suspicious PowerShell Child Processes
Suspicious execution chain found
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1409768 Sample: index.php.ps1 Startdate: 15/03/2024 Architecture: WINDOWS Score: 80 14 mopuketo.space 2->14 16 Antivirus detection for URL or domain 2->16 18 Antivirus / Scanner detection for submitted sample 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 2 other signatures 2->22 7 powershell.exe 14 17 2->7         started        signatures3 process4 signatures5 24 Suspicious execution chain found 7->24 10 conhost.exe 7->10         started        12 rundll32.exe 7->12         started        process6
Threat name:
Win32.Trojan.Boxter
Status:
Malicious
First seen:
2021-10-20 02:24:36 UTC
File Type:
Text (Batch)
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Malware Config
Dropper Extraction:
http://mopuketo.space/222g100/main.php
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_PowerShell_Download_Temp_Rundll
Author:SECUINFRA Falcon Team
Description:Detect a Download to %temp% and execution with rundll32.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Gozi

PowerShell (PS) ps1 ce412cd3202e853b57d0756427ee57e2477b1d8d9e694fd3f7dac8fcd3d05009

(this sample)

Comments



Avatar
commented on 2024-03-15 13:32:58 UTC

IEV was an email containing a Google APIs link.

C2 IOCs for BazaarLoader / BazaarBackdoor sample. IEV was likely a spearphishing email containing a GoogleAPIs link which led to suspicious domains. DNS traffic to GoogleAPIs consistently used 128 in the last octet.

Stage 1 payload called "index.php" was actually a PowerShell script to pull additional binaries down to the target system from various C2 domains.
Attack binary Stage 2 was called "main.php" and was the actually executable. Upon execution the attack binary at Stage 2 would attempt to check for debuggers for anti-analysis and attempt to unpack itself in a separate area of memory. Stage 2 also dropped a DLL file called Soon.dll.

After execution of Stage-2, the malware would begin HTTP POST traffic of encrypted data within the URI for data exfiltration.

Stage-2 Execution Artifacts:
"C:\Users\USERNAME\AppData\Local\Temp\leUafP.dat"
"c:\baby\high\ease\gener\side \soon.pdb"