🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ae25d7dfc31bcbb0ceb42e5d214a80804ba0305fab9b7475c79e5d7e5d9ba58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 4ae25d7dfc31bcbb0ceb42e5d214a80804ba0305fab9b7475c79e5d7e5d9ba58
SHA3-384 hash: 7a0f42a43427474655f1742ed99dbcbbffb7b803d7a43a3ba07dfdda8a36637ba82c468d51f8bf405bea81fa34c5482e
SHA1 hash: dbde22184781893a232a12859902421b2b087e39
MD5 hash: 128aff0507cec36712bc3548bdfa7cc6
humanhash: fanta-chicken-asparagus-sixteen
File name:contrib13.hta
Download: download sample
Signature Gozi
File size:10'299 bytes
First seen:2022-03-08 07:50:58 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:application/octet-stream
ssdeep 192:1YtjKdKuEbaL4Aq/I2rDvXxf7fujuSBXgYyuXS58vLC/f1LKaxTSleb5N302U/nO:1Y4NEbJA4DvX9ujukwy+X1txTSlez7X
TLSH T15A225B0C723B90EA9307B4ABD9A61F4FE104CCE6DFE2C1C07844578669ADB564B007AD
Reporter JAMESWT_WT
Tags:Gozi hta isfb mise Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
282
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script.Trojan.Generic
Status:
Suspicious
First seen:
2022-03-08 07:51:07 UTC
File Type:
Binary
AV detection:
11 of 27 (40.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments