🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e233642b9cb70dfe4e1fef85988b937e7461dbd41eafbd59694f65e5ddef28f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 11


Intelligence 11 IOCs YARA 7 File information Comments

SHA256 hash: e233642b9cb70dfe4e1fef85988b937e7461dbd41eafbd59694f65e5ddef28f4
SHA3-384 hash: 75d108970f88d6946e851444357dae6170e107f23b056ce7b3a644f5e100172a1d867e0ff9d3944fa62d9b89a55823b8
SHA1 hash: 07658014aefe68ef5f1bc9c19552b371d7aabd70
MD5 hash: d883ae7403f3adee8c0831c3aac4c208
humanhash: fish-sierra-freddie-fix
File name:LisectAVT_2403002C_65.exe
Download: download sample
Signature Gozi
File size:270'854 bytes
First seen:2024-07-25 01:49:38 UTC
Last seen:2024-07-25 02:23:07 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7c239b12229195f29dde016e51036cf2 (1 x Gozi)
ssdeep 6144:PNdMYdCojCslz3q43XjsEV+FAmpRYtxslEXcMiECHlkTE:VdpdCeqsj90ppy0qXrZgaE
TLSH T19C4412B3B48C0475EBC207B1A5F8BE21A772678D97027F9243209D4F0D9456A933E79A
TrID 48.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
16.4% (.EXE) Win64 Executable (generic) (10523/12/4)
10.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.0% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter Anonymous
Tags:exe Gozi


Avatar
Anonymous
this malware sample is very nasty!

Intelligence


File Origin
# of uploads :
2
# of downloads :
394
Origin country :
CN CN
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin makecab microsoft_visual_cc overlay packed reg rundll32 shell32 ursnif
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
76 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2024-07-25 01:50:12 UTC
File Type:
PE (Exe)
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:4099 discovery isfb
Behaviour
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
bc42ff58b15ccf03e88ffc7bc5bd9da1a554e6c3f3c3affb6a3a5fce217dd814
MD5 hash:
23a0647fdebbc168d420ad7680b8223c
SHA1 hash:
78ac6c30afb0e5e93802459515d11a6ea5b54c91
Detections:
ISFB_Main
SH256 hash:
e4c4b9965dc084b4ee6d577d7fca6c3a9c7460b2dd484c64147a7f303e8e70ea
MD5 hash:
8c61fbaefb7f7f254aa7b9920adb27df
SHA1 hash:
c829137ee3cb93e67f07ac75a9d66d2febeeacdd
Detections:
ISFB_Main win_isfb_a5
SH256 hash:
e233642b9cb70dfe4e1fef85988b937e7461dbd41eafbd59694f65e5ddef28f4
MD5 hash:
d883ae7403f3adee8c0831c3aac4c208
SHA1 hash:
07658014aefe68ef5f1bc9c19552b371d7aabd70
Detections:
ISFB_Main win_isfb_a5 Ursnif
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:malware_Ursnif_strings
Author:JPCERT/CC Incident Response Group
Description:detect Ursnif(a.k.a. Dreambot, Gozi, ISFB) in memory
Reference:internal research
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:Ursnif
Author:JPCERT/CC Incident Response Group
Description:detect Ursnif(a.k.a. Dreambot, Gozi, ISFB) in memory
Reference:internal research
Rule name:Ursnif3
Author:kevoreilly
Description:Ursnif Payload
Rule name:Windows_Trojan_Gozi_261f5ac5
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Gozi

Executable exe e233642b9cb70dfe4e1fef85988b937e7461dbd41eafbd59694f65e5ddef28f4

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::ConvertStringSecurityDescriptorToSecurityDescriptorA
KERNEL_APIManipulates Windows Kernel & Driversntdll.dll::RtlInitUnicodeString
ntdll.dll::ZwClose
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::GetTokenInformation
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteExA
SHELL32.dll::ShellExecuteA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
ntdll.dll::ZwOpenProcessToken
ntdll.dll::ZwOpenProcess
KERNEL32.dll::OpenProcess
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::VirtualAllocEx
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::GetVolumeInformationA
KERNEL32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileA
ntdll.dll::ZwCreateFile
KERNEL32.dll::CreateFileA
KERNEL32.dll::DeleteFileA
KERNEL32.dll::MoveFileExA
KERNEL32.dll::GetWindowsDirectoryA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegOpenKeyA
ADVAPI32.dll::RegQueryValueExA
ADVAPI32.dll::RegSetValueExA

Comments