🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3cd2555ba8ae12d5462af8139b65c04a964f4bdbe9909fcb92e158fd526d9d75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3cd2555ba8ae12d5462af8139b65c04a964f4bdbe9909fcb92e158fd526d9d75
SHA3-384 hash: 63879fe79f76174db5ddebe04da680b18c1fead544c51120fc575a2e354664e74bb810280cfcd01ff6a0358f20318665
SHA1 hash: 56e49c7d7b425e23286960f0d13d05c035191f5b
MD5 hash: fe0bcc4ff67afc3b9f9851d10191cb91
humanhash: carolina-whiskey-indigo-alabama
File name:comitato_115.zip
Download: download sample
Signature Gozi
File size:2'006 bytes
First seen:2022-03-15 11:51:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9wlIJV94g7NEGD91aLWtKMaJIth6cPWlZY8aFZufbp:sIbTzauuIzzWlZY8aFYp
TLSH T15041084280824C02F45DE6FAE460A2D161A034386CEC73B5FA37ECA145E5FC1664770E
Reporter JAMESWT_WT
Tags:Gozi isfb mise Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
381
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive mshta powershell
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://tradelinks.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments