🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4dd8c8adb2ed29ead05e4aa464f0b8e82e4998d6b3a8250fde4255779c08f3dc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4dd8c8adb2ed29ead05e4aa464f0b8e82e4998d6b3a8250fde4255779c08f3dc
SHA3-384 hash: 7e1713214acd0ec4dcca744a0b69efe579024da2ec26ebb2f35a1dfaaed97e82ac15cb4888f8220b40452ed9fa66bf7d
SHA1 hash: 728b1b72453d5d430f148973f2a3dc7cf1e5145b
MD5 hash: fe4dd5d5c3a68509dfd8830cb86dae23
humanhash: juliet-one-blue-angel
File name:Informazione_09.vbe
Download: download sample
Signature Gozi
File size:212 bytes
First seen:2022-02-08 13:20:12 UTC
Last seen:Never
File type:Visual Basic Script (vbe) vbe
MIME type:application/octet-stream
ssdeep 6:G8D8gZrsxROM2+WHLXELq8Iwn/J2XKDPXbFn:G8DxtsXjWrYqLwn/JUKDvpn
TLSH T103D022F57E02C0C8F4AF33062E86F9E4688AFA50F48A960C70496469011035EC249B60
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi isfb Ursnif vbe

Intelligence


File Origin
# of uploads :
1
# of downloads :
333
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-WScript.Trojan.Ursnif
Status:
Malicious
First seen:
2022-02-08 13:22:51 UTC
File Type:
Binary
Extracted files:
1
AV detection:
8 of 27 (29.63%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments