🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f6f3a62c3e0f4ecf92d138d069dffffb4e75ebdee6c86700918db72a85eb88e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4f6f3a62c3e0f4ecf92d138d069dffffb4e75ebdee6c86700918db72a85eb88e
SHA3-384 hash: 2257f0135b0ee05d195af34975f7e9b4b2370faabc64a063b700b6cb68264d221ff49bbb5c8dfced0e372b9abf7d51ac
SHA1 hash: a0f972f8c75bdaf4843f7dba8874a1bf7213a3d6
MD5 hash: 2ce82ff51f8ff2208420694a737532aa
humanhash: fifteen-speaker-shade-leopard
File name:ECCTransp.zip
Download: download sample
Signature Gozi
File size:1'711'927 bytes
First seen:2022-12-02 20:15:07 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:9y0oKk2QyRn0mIxVe9+ZQDLRzEddmIDacmdN6pC/+WZ7vb1KQ0zstAWT:9ya0VM9cQDedd+bXd7TG8L
TLSH T1E685CD2210E1CB91D749707983CA3A277F77E60A70379E5EA6F1E16BEA6217D8C14DC0
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter k3dg3___
Tags:Gozi LDR4 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:ECCTransp_Bill.pdf..lnk
File size:308'021'265 bytes
SHA256 hash: 57c7c4c5d1bf42f74b917408b273b759cbbac7733cc4e3be679f36549cd1266c
MD5 hash: a60c5988465f9835200b1919c082c2cb
MIME type:application/octet-stream
Signature Gozi
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.GenAutorunLnkFile
Status:
Malicious
First seen:
2022-12-02 20:18:24 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
4 of 41 (9.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Gozi

zip 4f6f3a62c3e0f4ecf92d138d069dffffb4e75ebdee6c86700918db72a85eb88e

(this sample)

  
Delivery method
Distributed via e-mail link

Comments