🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09d47b7a8bfae1425d2cc0d20ebe950b649fafac6750d6d54e3fa78a9dfa90fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 09d47b7a8bfae1425d2cc0d20ebe950b649fafac6750d6d54e3fa78a9dfa90fe
SHA3-384 hash: aea4b81af37a5611c1ff44c1e82363a668d28a5ad936742fc3d10f183902daa745775bb4f1016b35a38beec2693174e5
SHA1 hash: 21977046aeea697c3c3a59929b40f6e033c55f3f
MD5 hash: 3e38385510dde2641e544cd396874aeb
humanhash: autumn-fourteen-social-golf
File name:Inv_7272023_from637606_583358.js
Download: download sample
Signature Gozi
File size:1'089'555 bytes
First seen:2023-07-28 07:31:17 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:EuxQ15BLCJ3V04xV04Y3C0ooWXrr3zvDk63PvKcurKG5VVVOKNGThF+++f:EuxQ15BLCZV04xV04Y3C0ooWXrr3zvDq
TLSH T10235F917374433370A5331926A5A52D9AF3DCC267311D060FA6C916C266DC78A3BAFEB
Reporter JAMESWT
Tags:first stage js Gozi Intuit ITA js Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
318
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
control expand lolbin masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
JScript performs obfuscated calls to suspicious functions
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments