🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b87771d315aba151defee69658d30f74777cf642f581fac2185b86b30aee164. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4b87771d315aba151defee69658d30f74777cf642f581fac2185b86b30aee164
SHA3-384 hash: 96902421611b515925dcffe7e10b555121dae6e8159b69ad57411a73ced8dc888406e7fc7e697c5b6fabffe992468c4a
SHA1 hash: de55e1f615f919e5e4f8db07a40a0909cd61d18b
MD5 hash: 69ad8b9b103576b314d172df027d9e1d
humanhash: illinois-harry-hotel-juliet
File name:Documento_17.vbe
Download: download sample
Signature Gozi
File size:260 bytes
First seen:2022-02-10 10:33:49 UTC
Last seen:Never
File type:Visual Basic Script (vbe) vbe
MIME type:application/octet-stream
ssdeep 6:GS/DoQjWUrsxROM2CH5u+5mkH1Cz1Uych0sO1JSwVHvXVS7n:GMDoQpsX7V4kHW1Uychn0z1M7n
TLSH T154D09510C374C5C05C87150CBA64B761D92473395507A512120A3FDA610F0DBC6E8F3F
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi Ursnif vbe

Intelligence


File Origin
# of uploads :
1
# of downloads :
335
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-WScript.Downloader.Nemucod
Status:
Malicious
First seen:
2022-02-10 10:34:07 UTC
File Type:
Binary
Extracted files:
1
AV detection:
7 of 27 (25.93%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments