🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e93682935ab93fcb97ede1f8aba8076adf5e440a40a407a96f97c1b3af5188f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 2e93682935ab93fcb97ede1f8aba8076adf5e440a40a407a96f97c1b3af5188f
SHA3-384 hash: 5e223a55777cf693c4b5d99bddd740a8c16798a4ec1aa5e67c473e4291dc671c1a26f7b6bb74174d9ee6840550589398
SHA1 hash: 5535112912b97b970ba4b3b7d51896658beadb46
MD5 hash: 084628be20c0cc112964dc4efe6dbc93
humanhash: august-saturn-item-friend
File name:Documenti url
Download: download sample
Signature Gozi
File size:189 bytes
First seen:2023-03-24 06:45:04 UTC
Last seen:Never
File type:
MIME type:text/plain
ssdeep 3:HRAbABGQEb5oQsQaGRjlAXWkAoIvycAI9RyJ25YdimVVG/VClAWHn:HRYFJb5bsZGRG7NIvyc1yc54vVG/4xHn
TLSH T1E0C02208860DC069C042440FA058BC48AE0EB04808FB89181380DA876DD00CACD08ABE
TrID 91.6% (.URL) Windows URL shortcut (11000/1/2)
8.3% (.INI) Generic INI configuration (1000/1)
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi isfb MEF mise url Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
remote
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Methodology_Suspicious_Shortcut_SMB_URL
Author:@itsreallynick (Nick Carr), @QW5kcmV3 (Andrew Thompson)
Description:Detects remote SMB path for .URL persistence
Reference:https://twitter.com/cglyer/status/1176184798248919044

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments