🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46430bbb1d9b0711f1013f570898e873c34a1d3cd486b80b3f5f2af9cf9c896c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 46430bbb1d9b0711f1013f570898e873c34a1d3cd486b80b3f5f2af9cf9c896c
SHA3-384 hash: 5bad0c40e29b068256babef61329f489ce25a14abacc79602482b1c9728eafcd32bbc15c2505527836f5585b5f298cff
SHA1 hash: c417745a07d3895c9cc55c687b3f2ca77d5b36fc
MD5 hash: b3916883ed8017a17626bab708fcb1e8
humanhash: charlie-moon-floor-angel
File name:documentaz_661.vbs
Download: download sample
Signature Gozi
File size:4'006 bytes
First seen:2022-04-30 07:01:46 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 96:OiQefJqLGWCnASnHLE4vnF3O7T+yR3dz6UuDC2DpFG0AUL:OlefsiW4LHwmnF3G+yR3J6TW2tFZ
TLSH T1DD8127A8074FCAF8A613AC88C1D94A57EFA592264A3CE6C4CF70BEFB100457CD4F5498
Reporter abuse_ch
Tags:Gozi isfb Ursnif vbs


Avatar
abuse_ch
Gozi ISFB payload URL:
http://basesline.top/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
886
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
92 / 100
Signature
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Encrypted powershell cmdline option found
Multi AV Scanner detection for submitted file
PowerShell case anomaly found
Snort IDS alert for network traffic
Suspicious powershell command line found
Wscript starts Powershell (via cmd or directly)
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
Threat name:
Script-WScript.Trojan.Ursnif
Status:
Malicious
First seen:
2022-04-30 07:02:04 UTC
File Type:
Text (VBS)
AV detection:
9 of 26 (34.62%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://basesline.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments