🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 349d47be4a38242b25549567438628126f32f8ab236762d804b578bcbadbaeff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 349d47be4a38242b25549567438628126f32f8ab236762d804b578bcbadbaeff
SHA3-384 hash: 6860e86439980179be335094025117c87562e1093c42f036036fc8c9bd64bf4238ffa594df4189f8c8ee455af16994cb
SHA1 hash: 725df0fb6b973c443a4b62860ae6bde13a57d1d7
MD5 hash: 7fe3a539ee8b81c55ad6ad69e4e49101
humanhash: crazy-london-virginia-finch
File name:Fattura 2203-23_012(9).zip
Download: download sample
Signature Gozi
File size:1'960 bytes
First seen:2023-03-23 13:19:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9O6Iru/6nf2aZkHYFpL4gfpdruM5wxpeM6IKAQpBIOUlLpG449Z:0zq/6f2WkH2pL4AbvM6O4tUZpG449Z
TLSH T13441EA4DA5BC8508DBC287735EC28FC7717CB3191F14A1FA901968802B61334CBA2A65
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:EUROSPURGHI Gozi Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Fattura 3586 2023-300953.js
File size:6'504 bytes
SHA256 hash: 9e9bbcc818ebd460f4f0d7f66a32142427232a2f42316c93ee65d809c0e0927f
MD5 hash: 069f8ce804df7ea844d09777f28efd56
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Clean
File Type:
JS File
Payload URLs
URL
File name
https://google.com
JS File
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2023-03-23 13:20:11 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
6 of 37 (16.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments