🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e33a713b96b45e2b2e0da350c0fdaaf865139607066aadff3b67b0ced82ca8bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: e33a713b96b45e2b2e0da350c0fdaaf865139607066aadff3b67b0ced82ca8bc
SHA3-384 hash: a2cf95bf4bffc7d40205e3bf6353c69274d852fcb8e75b1edafb3c212d33cf43e4531cae505174a759f06b5ebc00b066
SHA1 hash: a68deea2d4f40bef60c7f605bc2aae9698259e69
MD5 hash: d0584edcc980ef43e697629ade83c54b
humanhash: shade-salami-tango-seven
File name:ini.dll
Download: download sample
Signature Gozi
File size:294'400 bytes
First seen:2023-05-26 11:36:03 UTC
Last seen:2023-05-26 12:15:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 3c3dece0112fc0b5785073312600144a (1 x Gozi)
ssdeep 6144:YwqnlTIaNrhtD+Cqdoazww2X/4TFEX0Ia:5qln1Y2MTGkI
TLSH T11D544B6E35A41DE8DD77C138C6829A22FA727C442334F6DB17A445A60F33BF16639329
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter abuse_ch
Tags:dll exe Gozi isfb Ursnif

Intelligence


File Origin
# of uploads :
2
# of downloads :
325
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
cd8393350f7cfc0762e09ee3b0a98002a1b9abf362caf5f210e717e1d4ebe53a
Verdict:
Malicious activity
Analysis date:
2023-05-26 09:38:43 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
lolbin packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
80 / 100
Signature
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected Ursnif
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 876269 Sample: ini.dll.exe Startdate: 26/05/2023 Architecture: WINDOWS Score: 80 52 Snort IDS alert for network traffic 2->52 54 Multi AV Scanner detection for domain / URL 2->54 56 Multi AV Scanner detection for submitted file 2->56 58 Yara detected Ursnif 2->58 9 loaddll64.exe 1 2->9         started        process3 process4 11 rundll32.exe 9->11         started        15 rundll32.exe 9->15         started        17 rundll32.exe 9->17         started        19 8 other processes 9->19 dnsIp5 48 sumarno.top 80.66.79.137, 443, 49710, 49720 RISS-ASRU Russian Federation 11->48 60 System process connects to network (likely due to code injection or exploit) 11->60 21 cmd.exe 2 11->21         started        23 cmd.exe 11->23         started        25 WerFault.exe 11->25         started        27 WerFault.exe 9 17->27         started        30 WerFault.exe 17 9 19->30         started        32 WerFault.exe 9 19->32         started        34 WerFault.exe 4 9 19->34         started        36 rundll32.exe 19->36         started        signatures6 process7 dnsIp8 38 net.exe 1 21->38         started        40 conhost.exe 21->40         started        42 conhost.exe 23->42         started        44 nltest.exe 23->44         started        50 192.168.2.1 unknown unknown 27->50 process9 process10 46 net1.exe 1 38->46         started       
Threat name:
Win64.Trojan.Ursnif
Status:
Suspicious
First seen:
2023-05-26 09:38:09 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
15 of 37 (40.54%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
e33a713b96b45e2b2e0da350c0fdaaf865139607066aadff3b67b0ced82ca8bc
MD5 hash:
d0584edcc980ef43e697629ade83c54b
SHA1 hash:
a68deea2d4f40bef60c7f605bc2aae9698259e69
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments