General
-
Target
9d3d9d40c90b409573e1c65457947fd42ec4945fa1c3589553d1189cf53f533e
-
Size
163KB
-
Sample
240620-bevbpazfke
-
MD5
580baae777aa29e699701e4fe8fff955
-
SHA1
4004d366cecf6a450198fc68f934b0e33d663e29
-
SHA256
9d3d9d40c90b409573e1c65457947fd42ec4945fa1c3589553d1189cf53f533e
-
SHA512
d01800bd14a35183c03a19d1c77d8741e41cc5648532137a5ae5eea1f3a8f8fb64f4b198c7bec0a75675b020de85160151ae11cb93c229e86ef8203d51d23d08
-
SSDEEP
3072:tCPp+GksSiNLAgGgNGfltOrWKDBr+yJb:MPpZSxWMfLOf
Static task
static1
Behavioral task
behavioral1
Sample
9d3d9d40c90b409573e1c65457947fd42ec4945fa1c3589553d1189cf53f533e.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
9d3d9d40c90b409573e1c65457947fd42ec4945fa1c3589553d1189cf53f533e.exe
Resource
win10v2004-20240508-en
Malware Config
Extracted
gozi
Targets
-
-
Target
9d3d9d40c90b409573e1c65457947fd42ec4945fa1c3589553d1189cf53f533e
-
Size
163KB
-
MD5
580baae777aa29e699701e4fe8fff955
-
SHA1
4004d366cecf6a450198fc68f934b0e33d663e29
-
SHA256
9d3d9d40c90b409573e1c65457947fd42ec4945fa1c3589553d1189cf53f533e
-
SHA512
d01800bd14a35183c03a19d1c77d8741e41cc5648532137a5ae5eea1f3a8f8fb64f4b198c7bec0a75675b020de85160151ae11cb93c229e86ef8203d51d23d08
-
SSDEEP
3072:tCPp+GksSiNLAgGgNGfltOrWKDBr+yJb:MPpZSxWMfLOf
Score10/10-
Adds autorun key to be loaded by Explorer.exe on startup
-
Detects executables built or packed with MPress PE compressor
-
UPX dump on OEP (original entry point)
-
Executes dropped EXE
-
Loads dropped DLL
-
Drops file in System32 directory
-