🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6173e77438ab03089ea688eade0d801c4083a7c73e9cb1e7c4f57ae0c6034832. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6173e77438ab03089ea688eade0d801c4083a7c73e9cb1e7c4f57ae0c6034832
SHA3-384 hash: ee6c194eb299a79300fcee3aa4d6e8d1b125d73f130c636c2d3bfdd38c94e0b67fb5f17ba465e12d1ec45b98cb55584a
SHA1 hash: 2a0faf993f1a5cb3e664ee66c51d9077d9590775
MD5 hash: 936f83f913128e56d1fda0f70ff4afbf
humanhash: bluebird-beryllium-grey-berlin
File name:stilak32
Download: download sample
Signature Gozi
File size:335'512 bytes
First seen:2023-03-20 15:13:39 UTC
Last seen:Never
File type:unknown
MIME type:application/octet-stream
ssdeep 6144:Ti0D5ij4o+B2b1dcYWnKzT03hzEJZsxbA7nszbIAHew8oAaHS2LIjScthkudwLS/:mjBMqc9nKPIcZstA7nk8w8oAa7syOwLo
TLSH T15A6423CFFD024FE7CCADCC14DD166526531332A1A70DFD42E2669DE2755A69A3B032A0
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi isfb MEF mise plugin Ursnif ursnif plugin

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
IT IT
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

unknown 6173e77438ab03089ea688eade0d801c4083a7c73e9cb1e7c4f57ae0c6034832

(this sample)

  
Delivery method
Distributed via web download

Comments