General
-
Target
c7178b77eb74b0e4c0da1f35482ce140f5ee4bda0b6f806e8c29088812b0c3d7
-
Size
632KB
-
Sample
240624-k4g74avcjh
-
MD5
222831dc032b9cd1dad652a777419574
-
SHA1
37d45f0c42caddf9516b715bbec8db679ff3cff9
-
SHA256
c7178b77eb74b0e4c0da1f35482ce140f5ee4bda0b6f806e8c29088812b0c3d7
-
SHA512
2f9778d283d5cb7467332924f7fef8e1e576a41fa4c572e6786632444f9aa82de31873e711324170e46cb7bb893ce0fa43e27d7608fa94a40eeecf4dd07a8039
-
SSDEEP
12288:wRWNcr8oxnLUiPclPA0DCQLsehJA3LQiEorgiYSsrGhtcLQaX:TNBILVIoQCoRJAke1rsrQtsJ
Static task
static1
Behavioral task
behavioral1
Sample
c7178b77eb74b0e4c0da1f35482ce140f5ee4bda0b6f806e8c29088812b0c3d7.exe
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
c7178b77eb74b0e4c0da1f35482ce140f5ee4bda0b6f806e8c29088812b0c3d7.exe
Resource
win10v2004-20240226-en
Malware Config
Extracted
gozi
Extracted
gozi
3000
unikymprogress.ru
ferarirecord.ru
-
exe_type
worker
-
server_id
12
Targets
-
-
Target
c7178b77eb74b0e4c0da1f35482ce140f5ee4bda0b6f806e8c29088812b0c3d7
-
Size
632KB
-
MD5
222831dc032b9cd1dad652a777419574
-
SHA1
37d45f0c42caddf9516b715bbec8db679ff3cff9
-
SHA256
c7178b77eb74b0e4c0da1f35482ce140f5ee4bda0b6f806e8c29088812b0c3d7
-
SHA512
2f9778d283d5cb7467332924f7fef8e1e576a41fa4c572e6786632444f9aa82de31873e711324170e46cb7bb893ce0fa43e27d7608fa94a40eeecf4dd07a8039
-
SSDEEP
12288:wRWNcr8oxnLUiPclPA0DCQLsehJA3LQiEorgiYSsrGhtcLQaX:TNBILVIoQCoRJAke1rsrQtsJ
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-