MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5cf7cd1382587ee1b71f4efbde4899b2b370db79a868e5fbabe8fdffaa711f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: e5cf7cd1382587ee1b71f4efbde4899b2b370db79a868e5fbabe8fdffaa711f0
SHA3-384 hash: 60c5ce70c19da9c1c41e505c59d2b490b8cbe108c08bd9166f1ffe2f79adbe8a943764c83b63f41fc5576f173a605b9b
SHA1 hash: 004e8fced5a26dbd02547b8fc162ef88999c8b5b
MD5 hash: cd82705318c7f924f2fbf0d21baba14c
humanhash: whiskey-edward-johnny-uranus
File name:ManagerAuthor.dll
Download: download sample
Signature Gozi
File size:556'032 bytes
First seen:2021-07-26 10:10:17 UTC
Last seen:2021-07-26 10:47:19 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash e4610620ffecb8f4b7fa684f2d9954ab (1 x Gozi)
ssdeep 12288:YCstyuJqgTlgguOjQkz9cPe3wuc7DU8+bPQ6zuZNSp:ds0MqghEOjHz8U8+7vz
TLSH T14CC4AD10B681E532D1F362354F23D6A4135D78281B3146EF33E82ABF1F694E366397A6
Reporter 0x746f6d6669
Tags:dll Gozi

Intelligence


File Origin
# of uploads :
2
# of downloads :
234
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 454113 Sample: ManagerAuthor.dll Startdate: 26/07/2021 Architecture: WINDOWS Score: 48 19 Multi AV Scanner detection for submitted file 2->19 7 loaddll32.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        15 2 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Gathering data
Result
Malware family:
gozi_ifsb
Score:
  10/10
Tags:
family:gozi_ifsb botnet:1212 banker trojan
Behaviour
Suspicious use of WriteProcessMemory
Gozi, Gozi IFSB
Malware Config
C2 Extraction:
yahoo.com
oldmass31.xyz
poklamens9.xyz
Unpacked files
SH256 hash:
ae9b4bd40cbcde52421d4f91489ff5e47f47e2322cd31ea29beab8bf83c53f1b
MD5 hash:
ee5dba5bb1f53904b896581e4fe45eaa
SHA1 hash:
993db4fffee189fc020a64ae5e5ef38436a3594c
Detections:
win_isfb_auto
SH256 hash:
e5cf7cd1382587ee1b71f4efbde4899b2b370db79a868e5fbabe8fdffaa711f0
MD5 hash:
cd82705318c7f924f2fbf0d21baba14c
SHA1 hash:
004e8fced5a26dbd02547b8fc162ef88999c8b5b
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments