🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c8074eb3f767399724b0f430c4697aa5bb509175c8e7f2f38ce2fc4df2914fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5c8074eb3f767399724b0f430c4697aa5bb509175c8e7f2f38ce2fc4df2914fd
SHA3-384 hash: 7d962c871a19b67cfbe5e9b35cb7f7fc5ab61f3c3e279b0df25ae22fc1be9a01110835d9142cca452b2f02b846ef5d26
SHA1 hash: 8d95bb789941e4b86d8c740068f4cf87e5b2d4f5
MD5 hash: 62fa4397665c234642de0cd966ba9305
humanhash: timing-alanine-king-alanine
File name:accluso_169.zip
Download: download sample
Signature Gozi
File size:2'000 bytes
First seen:2022-03-15 11:51:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9Y1TDh/IviVxxz/M/9z/FUH2eCcU1WkJqUTiLEmwZPSgi:6Dh/9VTzM/9/eClWkJ74EmwZqgi
TLSH T104410A3842A2A149EC1D7F315753AF0A1FA1E6034458AC7AC24986A16D125FBEC83811
Reporter JAMESWT_WT
Tags:Gozi mise Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
343
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive mshta powershell
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://tradelink.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments