🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02cd0843b225fa8bc8135dcf8634b394dfdfe37c69881a63c8321d3b233a652f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 02cd0843b225fa8bc8135dcf8634b394dfdfe37c69881a63c8321d3b233a652f
SHA3-384 hash: 9a8aacaeda2f4647f40a470195fc7e2aaa6b2b577176e3f8b90bc0b251d5f0b93fd5b71a19e20795d9791d785057c7e4
SHA1 hash: 59f25356d05f6b983eeefd610847a3396b382679
MD5 hash: c7d71dcf9ed43b396dee931cdc7745b6
humanhash: illinois-tennis-april-mobile
File name:Invoice_09142023_9528535955.zip
Download: download sample
Signature Gozi
File size:429'865 bytes
First seen:2023-09-14 17:02:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:ryUCyYciwP/DoZRETEGQH9jLty/hpbGadDqMfHUSXpIjPsvI:+UCy1X/DoRtdjLtyfRlqKR+jkg
TLSH T197942323A8F477590E4B21377B3A15843A44F8ED082DF943919A9742953BDC69F24B3D
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:goamiev-com Gozi zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Inv_09142023_269230_849915.js
File size:1'239'820 bytes
SHA256 hash: 19837a69a1e4ad7a8b720313edb7e0cf8c8448c3e39adb20ee6d16e5aeb2c71f
MD5 hash: e9c00339613b1ae346163c4b744f73a5
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Payload URLs
URL
File name
https://wiki.mozilla.org/Security:Renegotiation#security.ssl.treat_unsafe_negotiation_as_broken
JS File
Threat name:
Script-JS.Malware.Callisto
Status:
Malicious
First seen:
2023-09-14 17:03:07 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments