🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eed8a89080cb158492a0a8a623a4699c73e3edce560f23e7ca948a5ff0fc810e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: eed8a89080cb158492a0a8a623a4699c73e3edce560f23e7ca948a5ff0fc810e
SHA3-384 hash: f0e2a841290fcea92e9e432053afe4de437268eed6bf3c5270e0579a078c0b75901e4ba630460dd2dab46eb7eb8f5990
SHA1 hash: 536eaae3be7f1bbb77944d9e320aefed304a1642
MD5 hash: c842aadec571a4f88b08b9adbb4c1285
humanhash: steak-foxtrot-cup-arizona
File name:eed8a89080cb158492a0a8a623a4699c73e3edce560f23e7ca948a5ff0fc810e
Download: download sample
Signature Gozi
File size:430'592 bytes
First seen:2020-03-23 16:19:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c4310efa04612394c57bccc1000d7c7d (1 x Gozi)
ssdeep 6144:FTNfS1ComT7nRhGE/bBdi8KKLuyEax3whIqkgU+Vkx96JjW95dd82HwgNVLRlSqv:FTNfgm7nLGEjBQ8KKPdDpg5jupHhxW2
Threatray 384 similar samples on MalwareBazaar
TLSH 1494BE513780F078D172483771A5AF23467DBC215FA64AD773C06B2E96712C2E632BAB
Reporter Marco_Ramilli
Tags:exe Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2019-03-26 14:15:13 UTC
File Type:
PE (Exe)
Extracted files:
17
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

Executable exe eed8a89080cb158492a0a8a623a4699c73e3edce560f23e7ca948a5ff0fc810e

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyW
ADVAPI32.dll::RegQueryValueExW

Comments