General

  • Target

    5592f7cd87be75bbe942ebe124ab5e3b9c3e79c3ba6e2c1a5d3806507b9a365e

  • Size

    344KB

  • Sample

    240624-k37rcsvbpf

  • MD5

    b49d5aa9929e401eac02d9c10ec17b17

  • SHA1

    ee0d9a91f52de9b74b8de36e25c2de91d008cee5

  • SHA256

    5592f7cd87be75bbe942ebe124ab5e3b9c3e79c3ba6e2c1a5d3806507b9a365e

  • SHA512

    7ee8260cf4ebd4875f0718652e80fae4b64c57f84cb60736998a6d59bf0131e862b00362ce9b7efbcd4732ce8d749176c8a74e816511b7b86a39c07b0d7293f0

  • SSDEEP

    6144:1ULalLLjn9myvyirAmyl+XO5gGVE2c378vVjk6KdfNj7cW1pAIB:HlLX9myvya3HEzKL82dfiWpAIB

Score
10/10

Malware Config

Extracted

Family

gozi

Extracted

Family

gozi

Botnet

1000

C2

bonkacho.com

ihakispamhous.ru

gazuralnews.ru

gazitivaton.ru

Attributes
  • build

    204439

  • exe_type

    worker

  • server_id

    12

rsa_pubkey.plain
serpent.plain

Targets

    • Target

      5592f7cd87be75bbe942ebe124ab5e3b9c3e79c3ba6e2c1a5d3806507b9a365e

    • Size

      344KB

    • MD5

      b49d5aa9929e401eac02d9c10ec17b17

    • SHA1

      ee0d9a91f52de9b74b8de36e25c2de91d008cee5

    • SHA256

      5592f7cd87be75bbe942ebe124ab5e3b9c3e79c3ba6e2c1a5d3806507b9a365e

    • SHA512

      7ee8260cf4ebd4875f0718652e80fae4b64c57f84cb60736998a6d59bf0131e862b00362ce9b7efbcd4732ce8d749176c8a74e816511b7b86a39c07b0d7293f0

    • SSDEEP

      6144:1ULalLLjn9myvyirAmyl+XO5gGVE2c378vVjk6KdfNj7cW1pAIB:HlLX9myvya3HEzKL82dfiWpAIB

    Score
    1/10

MITRE ATT&CK Matrix

Tasks