General

  • Target

    installer.exe

  • Size

    195KB

  • MD5

    9dd7f4587140ec81cc261c6d05bac60b

  • SHA1

    6e999875685482810bb236383033195d329b923c

  • SHA256

    5ecf8bf6a98fe1380171b15bafdd0523f2b85d27e7bc4cb73e36a6717a15b93f

  • SHA512

    077224198ea5ac2d9b64a8fca1eb9141be35cee5ed4a625445024dc0939e797450ae7a94d9cb1ae392c7c24dfb8eb6dcd3a0cf2fdcd456640c71467538bb7ee1

  • SSDEEP

    6144:KbemuOXxbzS5llg9JCWWRipfrA4is0rA:KjxxvSl6Fai9rA4iJ

Score
10/10

Malware Config

Extracted

Family

gozi

Extracted

Family

gozi

Botnet

1000

C2

repeseparation.ru

Attributes
  • exe_type

    worker

  • server_id

    12

rsa_pubkey.plain
serpent.plain

Signatures

  • Gozi family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • installer.exe
    .exe windows:4 windows x86 arch:x86

    0491aaa454ef721ff8f93ea179f9b75c


    Headers

    Imports

    Sections