🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 352d8ab5de8d9a1cc7d2b7257a8ab024d9df71426c498d489a0b1e23ec0c0ed0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 352d8ab5de8d9a1cc7d2b7257a8ab024d9df71426c498d489a0b1e23ec0c0ed0
SHA3-384 hash: 016b07e33712f066aef4a8170f046cb180f9a640e14a5269e45b7f9c535a341fc1da6ed4d1f8995932b2c77d20ce2c66
SHA1 hash: f0a4cbdcbce6d512b87359d24e4f1f9c1330dfaf
MD5 hash: 079dacd14f45e6d8f6d3784f181a952d
humanhash: west-twenty-stream-montana
File name:1 Total New Invoices - Wednesday May 17 2023_1058.js
Download: download sample
Signature Gozi
File size:22'514 bytes
First seen:2023-05-19 09:05:12 UTC
Last seen:2023-05-31 10:34:35 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:j03wqvR/MfljerPlBfLo74jDROj68nx2tc:jOwqvR/yjyDfLQ4jAjZgtc
TLSH T116A284E052C93CBD543771F1192941E1D9B68869BA5E2CA4F06DB01CF71CF24E2BAC6B
Reporter madjack_red
Tags:Gozi js vipbeed-com

Intelligence


File Origin
# of uploads :
4
# of downloads :
269
Origin country :
GB GB
Vendor Threat Intelligence
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
JavaScript source code contains functionality to generate code involving HTTP requests or file downloads
JScript performs obfuscated calls to suspicious functions
Sample has a suspicious name (potential lure to open the executable)
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments