🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1f1ad41fe174f963cf89802ccb16d1afcf7c827040e20b414ffa44e2c830d2b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1f1ad41fe174f963cf89802ccb16d1afcf7c827040e20b414ffa44e2c830d2b2
SHA3-384 hash: c777351bdfc8a14d29ce10cd2b4a50f8171f9a6c6171ef859a44f3d6a4d4c8cd19556d630f402a2b2435c1fcb5489c68
SHA1 hash: 49e9156b3efab741fbe751eda20de45491d18d96
MD5 hash: af669c0dfce54fac328717a8238349f1
humanhash: september-floor-oven-minnesota
File name:criterio580.hta
Download: download sample
Signature Gozi
File size:10'492 bytes
First seen:2022-03-07 12:16:39 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:application/octet-stream
ssdeep 192:S4YIrlfyTjTbTNli4Ez+2G8ob50fenLal21IppHw4vmhW07GgIT1aTMujfQcSvnQ:S4YRvjU6nKe/6DHNmkxaLIR9Py
TLSH T13B224B2DB12BB598835360EFD87E2F1BE118DFE5DFEA40447059438228ADB899A1078D
Reporter JAMESWT_WT
Tags:Gozi hta isfb ITA mise Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
341
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-WScript.Trojan.Generic
Status:
Suspicious
First seen:
2022-03-07 12:17:09 UTC
File Type:
Binary
AV detection:
3 of 27 (11.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments