paladin316

Gozi_9bd1d88da5ad432179b072f03907c87b_bin_2019-07-15_11_30.txt

Jul 15th, 2019
3,135
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.42 KB | None | 0 0
  1.  
  2. * MalFamily: "Gozi"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Gozi_9bd1d88da5ad432179b072f03907c87b.bin"
  7. * File Size: 639488
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "7c75fa89667a5e9b36d0964eeef1a5b53f06ab828289dda7c451507eb5ee707b"
  10. * MD5: "9bd1d88da5ad432179b072f03907c87b"
  11. * SHA1: "1f7b1d7e901a3b376ae3db13fa8d28e16b996a61"
  12. * SHA512: "8f79dc5b4cefea46335af31f7c674f3296d9514e9488220de1d31472a5acce29a157f23da0b3723746d2ee7dd0e7752536ff3a6c9ed05de6b61eb7584bc55fbb"
  13. * CRC32: "F3C7230B"
  14. * SSDEEP: "12288:t6yNZssnrqn0CxdKVIOgwKgx1iaP6uDhR7XWsTgVD5EQNov7jWirv5Z/A:oyN6snrqn0CxgVIOgIBD6zVN/Norv5Z4"
  15.  
  16. * Process Execution:
  17. "Gozi_9bd1d88da5ad432179b072f03907c87b.bin",
  18. "control.exe",
  19. "rundll32.exe",
  20. "explorer.exe"
  21.  
  22.  
  23. * Executed Commands:
  24. "C:\\Windows\\system32\\control.exe /?",
  25. "\"C:\\Windows\\system32\\rundll32.exe\" Shell32.dll,Control_RunDLL /?",
  26. "%SystemRoot%\\system32\\rundll32.exe Shell32.dll,Control_RunDLL /?"
  27.  
  28.  
  29. * Signatures Detected:
  30.  
  31. "Description": "Creates RWX memory",
  32. "Details":
  33.  
  34.  
  35. "Description": "Possible date expiration check, exits too soon after checking local time",
  36. "Details":
  37.  
  38. "process": "control.exe, PID 2824"
  39.  
  40.  
  41.  
  42.  
  43. "Description": "Deletes its original binary from disk",
  44. "Details":
  45.  
  46.  
  47. "Description": "Executed a process and injected code into it, probably while unpacking",
  48. "Details":
  49.  
  50. "Injection": "Gozi_9bd1d88da5ad432179b072f03907c87b.bin(2924) -> control.exe(2824)"
  51.  
  52.  
  53.  
  54.  
  55. "Description": "Sniffs keystrokes",
  56. "Details":
  57.  
  58. "SetWindowsHookExA": "Process: explorer.exe(2004)"
  59.  
  60.  
  61.  
  62.  
  63. "Description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
  64. "Details":
  65.  
  66. "regkeyval": "HKEY_CURRENT_USER\\Software\\AppDataLow\\Software\\Microsoft\\0EEC6689-1584-7006-0F22-19A4B3765D18\\Client32"
  67.  
  68.  
  69. "regkeyval": "HKEY_CURRENT_USER\\Software\\AppDataLow\\Software\\Microsoft\\0EEC6689-1584-7006-0F22-19A4B3765D18\\Client64"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "Installs itself for autorun at Windows startup",
  75. "Details":
  76.  
  77. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\aecaM1M0"
  78.  
  79.  
  80. "data": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\ApiMM1M0\\aeevpisp.exe"
  81.  
  82.  
  83.  
  84.  
  85. "Description": "File has been identified by 44 Antiviruses on VirusTotal as malicious",
  86. "Details":
  87.  
  88. "MicroWorld-eScan": "Trojan.GenericKD.32132510"
  89.  
  90.  
  91. "FireEye": "Generic.mg.9bd1d88da5ad4321"
  92.  
  93.  
  94. "McAfee": "GCrab-FNZ!9BD1D88DA5AD"
  95.  
  96.  
  97. "Cylance": "Unsafe"
  98.  
  99.  
  100. "Alibaba": "TrojanBanker:Win32/Gozi.365aa294"
  101.  
  102.  
  103. "K7GW": "Trojan ( 00551f251 )"
  104.  
  105.  
  106. "K7AntiVirus": "Trojan ( 00551f251 )"
  107.  
  108.  
  109. "Arcabit": "Trojan.Generic.D1EA4D9E"
  110.  
  111.  
  112. "TrendMicro": "Trojan.Win32.BLACKMAIL.USXVPGA19"
  113.  
  114.  
  115. "Symantec": "Trojan Horse"
  116.  
  117.  
  118. "APEX": "Malicious"
  119.  
  120.  
  121. "Avast": "Win32:Malware-gen"
  122.  
  123.  
  124. "Kaspersky": "Trojan-Banker.Win32.Gozi.dnu"
  125.  
  126.  
  127. "BitDefender": "Trojan.GenericKD.32132510"
  128.  
  129.  
  130. "Paloalto": "generic.ml"
  131.  
  132.  
  133. "AegisLab": "Trojan.Win32.Malicious.4!c"
  134.  
  135.  
  136. "Tencent": "Win32.Trojan-banker.Gozi.Hxpx"
  137.  
  138.  
  139. "Endgame": "malicious (high confidence)"
  140.  
  141.  
  142. "Emsisoft": "Trojan.GenericKD.32132510 (B)"
  143.  
  144.  
  145. "Invincea": "heuristic"
  146.  
  147.  
  148. "McAfee-GW-Edition": "GCrab-FNZ!9BD1D88DA5AD"
  149.  
  150.  
  151. "Sophos": "Mal/Generic-S"
  152.  
  153.  
  154. "Ikarus": "Trojan.Win32.Crypt"
  155.  
  156.  
  157. "Cyren": "W32/Trojan.IKIR-2774"
  158.  
  159.  
  160. "Avira": "TR/Crypt.Agent.arxly"
  161.  
  162.  
  163. "Antiy-AVL": "TrojanBanker/Win32.Gozi"
  164.  
  165.  
  166. "Microsoft": "Trojan:Win32/Skeeyah.A!MTB"
  167.  
  168.  
  169. "ZoneAlarm": "Trojan-Banker.Win32.Gozi.dnu"
  170.  
  171.  
  172. "GData": "Trojan.GenericKD.32132510"
  173.  
  174.  
  175. "AhnLab-V3": "Trojan/Win32.Agent.C3330812"
  176.  
  177.  
  178. "Acronis": "suspicious"
  179.  
  180.  
  181. "VBA32": "BScope.Trojan.Chapak"
  182.  
  183.  
  184. "ALYac": "Trojan.GenericKD.32132510"
  185.  
  186.  
  187. "Ad-Aware": "Trojan.GenericKD.32132510"
  188.  
  189.  
  190. "Malwarebytes": "Trojan.MalPack.GS"
  191.  
  192.  
  193. "ESET-NOD32": "a variant of Win32/Kryptik.GUMA"
  194.  
  195.  
  196. "TrendMicro-HouseCall": "Trojan.Win32.BLACKMAIL.USXVPGA19"
  197.  
  198.  
  199. "Rising": "[email protected] (RDMK:+gDh8bhEcYpAlu3YXO5OGg)"
  200.  
  201.  
  202. "Fortinet": "W32/Kryptik.GUMO!tr"
  203.  
  204.  
  205. "AVG": "Win32:Malware-gen"
  206.  
  207.  
  208. "Cybereason": "malicious.e901a3"
  209.  
  210.  
  211. "Panda": "Trj/GdSda.A"
  212.  
  213.  
  214. "CrowdStrike": "win/malicious_confidence_90% (W)"
  215.  
  216.  
  217. "Qihoo-360": "Win32/Trojan.3c9"
  218.  
  219.  
  220.  
  221.  
  222. "Description": "Creates a copy of itself",
  223. "Details":
  224.  
  225. "copy": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\ApiMM1M0\\aeevpisp.exe"
  226.  
  227.  
  228.  
  229.  
  230.  
  231. * Started Service:
  232.  
  233. * Mutexes:
  234. "76AB94A1-5DAC-18C2-970A-E1CCBBDEA5C0",
  235. "Local\\CA7E941A-A1DF-8C74-7B9E-6580DFB269B4",
  236. "Local\\143F7FD9-631F-66FD-8D88-47FA113C6BCE",
  237. "Local\\C24B3540-3918-44E4-D316-7DB8B7AA016C",
  238. "D2C93950-09DF-D4DC-2326-4D4807BAD1FC",
  239. "7E83C072-C5D4-603F-3F92-C994E3E60D08"
  240.  
  241.  
  242. * Modified Files:
  243. "\\??\\mailslot\\slb6c",
  244. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\ApiMM1M0\\aeevpisp.exe",
  245. "\\??\\pipe\\A6CCF2CA-CD7B-C8EA-873A-517CAB0E1570"
  246.  
  247.  
  248. * Deleted Files:
  249. "C:\\Users\\user\\AppData\\Local\\Temp\\Gozi_9bd1d88da5ad432179b072f03907c87b.bin"
  250.  
  251.  
  252. * Modified Registry Keys:
  253. "HKEY_CURRENT_USER\\Software\\AppDataLow\\Software\\Microsoft\\0EEC6689-1584-7006-0F22-19A4B3765D18",
  254. "HKEY_CURRENT_USER\\Software\\AppDataLow\\Software\\Microsoft\\0EEC6689-1584-7006-0F22-19A4B3765D18\\Client32",
  255. "HKEY_CURRENT_USER\\Software\\AppDataLow\\Software\\Microsoft\\0EEC6689-1584-7006-0F22-19A4B3765D18\\Client64",
  256. "HKEY_CURRENT_USER\\Software\\AppDataLow\\Software\\Microsoft\\0EEC6689-1584-7006-0F22-19A4B3765D18\\Client",
  257. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\aecaM1M0",
  258. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnableSPDY3_0",
  259. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7\\pzq.rkr",
  260. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\HRZR_PGYFRFFVBA"
  261.  
  262.  
  263. * Deleted Registry Keys:
  264.  
  265. * DNS Communications:
  266.  
  267. "type": "A",
  268. "request": "interruption.ru",
  269. "answers":
  270.  
  271. "data": "",
  272. "type": "NXDOMAIN"
  273.  
  274.  
  275.  
  276.  
  277.  
  278. * Domains:
  279.  
  280. "ip": "",
  281. "domain": "interruption.ru"
  282.  
  283.  
  284.  
  285. * Network Communication - ICMP:
  286.  
  287. * Network Communication - HTTP:
  288.  
  289. * Network Communication - SMTP:
  290.  
  291. * Network Communication - Hosts:
  292.  
  293. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment