🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a44bf781e5ddd0a77dcaa97caafb1be31392fa6fc63891ff7e595318030b540. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4a44bf781e5ddd0a77dcaa97caafb1be31392fa6fc63891ff7e595318030b540
SHA3-384 hash: 84bdba584210d7840363b7e5671f0ab7807469dcc2c173f0ec568e6f2d304b8167003bb887f27db39a5b8f27b71d8851
SHA1 hash: b1d4a8da261109f7c55923938f0d7f3507792db2
MD5 hash: 32e7ae2c7ea17e394eec3262d00ca2cc
humanhash: high-yankee-mexico-whiskey
File name:Invoice_Details.zip
Download: download sample
Signature Gozi
File size:10'636 bytes
First seen:2023-07-18 16:31:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:7jRpAsVb6q6tIrRMpKZjYMgxhqeacz2PqhYhn/xrTKwswSo8eez:PTAsMqwIFMpKebDqzcz2VhprTKwGoTM
TLSH T1FB22AF5F52CD4D0FE5AAACF18E53DDACA72096A0840DBB42127D743047C5DE546E2FA3
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:20000 Gozi Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
141
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Invoice_Details.js
File size:43'342 bytes
SHA256 hash: 5e5722af27fc7ae05a9f9705ce1d680fec5fef27a67019c37e2bd768c8e7c07e
MD5 hash: 22067f54377e90dc3fdd5f384c1fe3ee
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd lolbin lolbin masquerade obfuscated replace rundll32
Threat name:
Script-JS.Downloader.Callisto
Status:
Malicious
First seen:
2023-07-18 16:32:06 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
11 of 25 (44.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Deletes itself
Executes dropped EXE
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments