🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5cd695c87c2b87290e167c8ef030d2858621153b058d8655afee049392a259d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5cd695c87c2b87290e167c8ef030d2858621153b058d8655afee049392a259d1
SHA3-384 hash: 1db644a11104a8f00136f44c2def86baa1a5f4bd16c1b34fbef18b5a24c6a8242ed6fe52f7eae0186b5c9e1622a47523
SHA1 hash: fbdf3b5b4cfdf2914bca84454112849a71226aa3
MD5 hash: 9a1925752de9adbb3e396de434f0bbbe
humanhash: cup-louisiana-spring-jupiter
File name:1 Total New Invoices - Wednesday May 17 2023[1].zip
Download: download sample
Signature Gozi
File size:23'488 bytes
First seen:2023-05-19 01:45:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:H1Gvrnr43r8+bDR8GequQABhWPzKE7H/vDcGh5I/tJmTMiOc14FEiM1yu7eRBGXZ:VGvA3rxDR8Wuo7KDw6tJmTMG4Ft+Z
TLSH T131B2D083550EF699A5FBA3D3E440ACF9586A036C616C4851108E39814FF667BDBC1CFB
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:Gozi vipbeed-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:1 Total New Invoices - Wednesday May 17 2023_1062.js
File size:60'286 bytes
SHA256 hash: bc5af652808a7a41406b22f148a9e6bb8f45bbad9e2b8e13679d6c545c00b63a
MD5 hash: 846dbf899645abb88a61103170dd6c5f
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
hyena virus
Threat name:
Binary.Malware.Generic
Status:
Suspicious
First seen:
2023-05-19 01:33:08 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
3 of 37 (8.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments