MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eec9887fb0a1a6157c82c1319dd32e9750d616a4dc31cdbb29b2ff75028fcf04. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: eec9887fb0a1a6157c82c1319dd32e9750d616a4dc31cdbb29b2ff75028fcf04
SHA3-384 hash: 6fca4b0f4484b9c7f4332a7bf18e2ba42e6605b6cb31fb3ec84e25997ff3251c70f8cac40f44b84c1dd8b8332b60e400
SHA1 hash: 69b3e1476205aac3e8912a87bbb2095f6c9d89ab
MD5 hash: 4ea313151ad65a9eb770b60fd991de63
humanhash: king-wolfram-pip-grey
File name:eec9887fb0a1a6157c82c1319dd32e9750d616a4dc31cdbb29b2ff75028fcf04
Download: download sample
Signature Gozi
File size:512'000 bytes
First seen:2020-03-23 16:19:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b0ea02f0383bddda090101ff160ddaf2 (1 x Gozi)
ssdeep 6144:dskb4sYym17ppdJr+t5zgKX2yMrAQkKbC9WX3s7GhE644kYmhS4/jbmirY33umqA:dqBx1KUKX2vrAQo9WXof47J4/7Y39Z
Threatray 254 similar samples on MalwareBazaar
TLSH 1CB45B01B6B0C03CF5F756F94DBE51A9983DBEA01B2580CF63C416EE5A25AE0AD31727
Reporter Marco_Ramilli
Tags:exe Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessW
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW

Comments