General

  • Target

    a67730ba508b131d8088ed0a03f5cd97_JaffaCakes118

  • Size

    250KB

  • Sample

    240613-tsx9lszenl

  • MD5

    a67730ba508b131d8088ed0a03f5cd97

  • SHA1

    6ca4377cae589afc9188518c75ba9da1158ec1c1

  • SHA256

    bc9a74b693d0fd8b64727d38d56e996bd6a1a926b6d91384bb6032af9c27cdf3

  • SHA512

    06c8462dbc275dfcde6699c457091ea068bd959d75a7d0e743ea63fb467c1f055d355d24b85a172e8af96745c51c753c889b21822f20ac8e2b25a25edf4d396b

  • SSDEEP

    3072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2

Malware Config

Extracted

Family

gozi

Attributes
  • build

    300913

Extracted

Family

gozi

Botnet

92020311

C2

https://appealingedge.xyz

Attributes
  • build

    300913

  • dga_base_url

    constitution.org/usdeclar.txt

  • dga_crc

    0x4eb7d2ca

  • dga_season

    10

  • dga_tlds

    com

    ru

    org

  • exe_type

    loader

  • non_target_locale

    RU

  • server_id

    12

  • url_path

    index.htm

rsa_pubkey.plain
serpent.plain

Targets

    • Target

      a67730ba508b131d8088ed0a03f5cd97_JaffaCakes118

    • Size

      250KB

    • MD5

      a67730ba508b131d8088ed0a03f5cd97

    • SHA1

      6ca4377cae589afc9188518c75ba9da1158ec1c1

    • SHA256

      bc9a74b693d0fd8b64727d38d56e996bd6a1a926b6d91384bb6032af9c27cdf3

    • SHA512

      06c8462dbc275dfcde6699c457091ea068bd959d75a7d0e743ea63fb467c1f055d355d24b85a172e8af96745c51c753c889b21822f20ac8e2b25a25edf4d396b

    • SSDEEP

      3072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

MITRE ATT&CK Matrix ATT&CK v13

Tasks