🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24fb3d70b0cbe72c141c213dd739470b18cefdf14460267ea64bf8e453aa7b75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 24fb3d70b0cbe72c141c213dd739470b18cefdf14460267ea64bf8e453aa7b75
SHA3-384 hash: eac6213e7926fa794e8c6a48ddb820a6be257d8a954a1bc7ba012b38c035bd0253ccf4cea9669e0af901e5faa2760ff0
SHA1 hash: dc6f1c76b4679b1704ec9f9e4705410696a68ff8
MD5 hash: b0ff08f0ac034d754ba4d589a881f20f
humanhash: carpet-queen-oranges-apart
File name:Agenzia_18.zip
Download: download sample
Signature Gozi
File size:391 bytes
First seen:2022-02-10 13:37:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6:5j1kDs7CjJsrC5i7ktRLW01fCcHTzGzY/1XLOPA+txxf6oB+lMn/l:5j1kDsO1srCsAtRL11fBfJgxx/aMt
TLSH T1E4E0C0D0ABCB8229E18DE63D9C0F9B5D92999E9CA0971687140B908E0E074CDBE5730B
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
310
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2022-02-10 13:38:10 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
3 of 43 (6.98%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments