Analysis

  • max time kernel
    141s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    19-06-2024 16:33

General

  • Target

    anopka4.exe

  • Size

    1003KB

  • MD5

    245dc39abf2c6aec5a14f7b7778bd562

  • SHA1

    b59c376b28c9c65123a2e94e8a22e4b0d604c0f2

  • SHA256

    9262dfd4bef2cac6c097b92a2df8deefdc56a53b7a24a9fd72bf978818c0e590

  • SHA512

    4cd440ecfc2e6ff080ff91edf7112b10a32620ef604aba281dd4ddca14ebc772e5720ec1efc9fde9e4b5d8875d76a08a33254cb9747562ffbfb270fd3895b32e

  • SSDEEP

    12288:X3wS4ZBG9rlLbdh5Qx9XNsjpaM1RJFbH7GsqgMMrzEYWNvlQ+5s8UgxyYPILEX0T:wSph5g2oo/FOlZRNk8JxysILguIZ

Score
10/10

Malware Config

Extracted

Family

gozi

Signatures

  • Gozi

    Gozi is a well-known and widely distributed banking trojan.

Processes

  • C:\Users\Admin\AppData\Local\Temp\anopka4.exe
    "C:\Users\Admin\AppData\Local\Temp\anopka4.exe"
    1⤵
      PID:2296

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2296-0-0x0000000000400000-0x0000000000505000-memory.dmp
      Filesize

      1.0MB

    • memory/2296-1-0x0000000000490000-0x0000000000493000-memory.dmp
      Filesize

      12KB

    • memory/2296-2-0x0000000000400000-0x0000000000505000-memory.dmp
      Filesize

      1.0MB

    • memory/2296-10-0x00000000002F0000-0x000000000032C000-memory.dmp
      Filesize

      240KB

    • memory/2296-3-0x00000000002F0000-0x000000000032C000-memory.dmp
      Filesize

      240KB