🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f84e0c6d7877be866064dd176f832737ae9cd04901913185c8e525efdcb9ee2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 15


Intelligence 15 IOCs YARA 2 File information Comments

SHA256 hash: f84e0c6d7877be866064dd176f832737ae9cd04901913185c8e525efdcb9ee2e
SHA3-384 hash: 20e63ad14d87c3e95340740cde6eda01297e278ea635720e1ca5ef60ef7326005fc8654b1a9479e3dad968541459aaa7
SHA1 hash: ffdbf44ae5db43c5210c5ef00b2b2d8192053dae
MD5 hash: 1f6822f8aab6189e0f9db8d6f820d9af
humanhash: timing-delta-mobile-fanta
File name:decode_5d598e3afe8736c96f6d2cc0a6509b12e9fc15d45afc070e7e9d5bd68946335e
Download: download sample
Signature Gozi
File size:37'376 bytes
First seen:2023-03-29 15:58:24 UTC
Last seen:2023-05-30 20:49:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1640d668d1471f340cbe565fe63522f6 (15 x Gozi)
ssdeep 768:gKbMPv5JLi5yOyV34OB9bl5n+iRjn9P1avZa9Bmr1h097mI5:g4MHLLi5pyt5+0zavZangX097m
TLSH T1BDF2E0E21CA24977EFCF90B44FBAE094B37295915E19C0881333CE6ED7A9D4161AB643
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter jstrosch
Tags:exe Gozi Ursnif

Intelligence


File Origin
# of uploads :
2
# of downloads :
300
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
decode_5d598e3afe8736c96f6d2cc0a6509b12e9fc15d45afc070e7e9d5bd68946335e
Verdict:
No threats detected
Analysis date:
2023-03-29 16:01:14 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Using the Windows Management Instrumentation requests
DNS request
Sending an HTTP GET request
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
MalwareBazaar
CheckCmdLine
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found API chain indicative of debugger detection
Found evasive API chain (may stop execution after checking system information)
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Writes or reads registry keys via WMI
Writes registry values via WMI
Yara detected Ursnif
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2023-03-29 15:59:05 UTC
File Type:
PE (Exe)
AV detection:
24 of 24 (100.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gozi botnet:1900 banker isfb trojan
Behaviour
Gozi
Malware Config
C2 Extraction:
tel12.msn.com
194.76.225.60
185.212.47.133
Unpacked files
SH256 hash:
437a7679dd60b9cc6fd4d34a6a74486d8f84e2965b1568191630f835211d3e10
MD5 hash:
4435bc98c1868f9a9078f930a201122e
SHA1 hash:
ed848d89e3f557f813fe0f3e8129d7b4efc85b5b
Detections:
ISFB_Main win_isfb_auto
SH256 hash:
f84e0c6d7877be866064dd176f832737ae9cd04901913185c8e525efdcb9ee2e
MD5 hash:
1f6822f8aab6189e0f9db8d6f820d9af
SHA1 hash:
ffdbf44ae5db43c5210c5ef00b2b2d8192053dae
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:UrsnifV3
Author:kevoreilly
Description:UrsnifV3 Payload
Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments