General

  • Target

    suzELhW.exe

  • Size

    13.1MB

  • Sample

    240705-2lknyazgmg

  • MD5

    048ac9cef1a2a0770e626f0ec9634df3

  • SHA1

    d14330ff37a2827043bbc40c50bc19879103dbe1

  • SHA256

    7c407b3c332035c19d6c08780fcf04017d9ad9f05b6ed06047d5341eca9201fe

  • SHA512

    7139e333f49db124a84d485b667e4a6ab3ad44e56b5c5e92c9fb1f1aae45673ba8cfa45b1e7610dc9db643966b5ff11551c4866775877144c22b3735f4832ece

  • SSDEEP

    196608:FUqGuGYdgOh3Ej4y2JnnouxSEFxlRhWNXZXEXp9g0FQ1RCzuLpJG5QDp:BGuPdgOhkWnnoQSEdM1EXTgQQ1Qz80K

Score
10/10

Malware Config

Extracted

Family

gozi

Targets

    • Target

      suzELhW.exe

    • Size

      13.1MB

    • MD5

      048ac9cef1a2a0770e626f0ec9634df3

    • SHA1

      d14330ff37a2827043bbc40c50bc19879103dbe1

    • SHA256

      7c407b3c332035c19d6c08780fcf04017d9ad9f05b6ed06047d5341eca9201fe

    • SHA512

      7139e333f49db124a84d485b667e4a6ab3ad44e56b5c5e92c9fb1f1aae45673ba8cfa45b1e7610dc9db643966b5ff11551c4866775877144c22b3735f4832ece

    • SSDEEP

      196608:FUqGuGYdgOh3Ej4y2JnnouxSEFxlRhWNXZXEXp9g0FQ1RCzuLpJG5QDp:BGuPdgOhkWnnoQSEdM1EXTgQQ1Qz80K

    Score
    10/10
    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks