MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 644b2bc164fb1118f399abd11f3e717491ae55560c042da604a9b784fc04c1f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 644b2bc164fb1118f399abd11f3e717491ae55560c042da604a9b784fc04c1f2
SHA3-384 hash: 491cbe7a03f91b29862ca3738bb355a038553cb02b002123b999dc67cce3f9ddca8fdd9309ab2692ac5dcb00bd9d13c6
SHA1 hash: db7a87a3689404360a4a55b40ef29c469086f49a
MD5 hash: 3e64c99d9a2a523893e9b1da64e2f605
humanhash: georgia-don-salami-golf
File name:RM2021OSO0327831072120210727104835.zip
Download: download sample
Signature Gozi
File size:12'860 bytes
First seen:2021-07-27 10:34:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:Bs0muxW/MKBNWgnJtJqzQ4qoVuMRD1jnVX:BsPuxW/MKbdJ6BXRZZ
TLSH T11142C048E946CCADDD23F1BB2CC87B507767A09039E01E45EF0B3D25679443EFA6A261
Reporter JAMESWT_WT
Tags:Gozi isfb pwRM2021OSO03 RM2021OSO03 Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
785
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2021-07-27 10:34:23 UTC
File Type:
Binary (Archive)
AV detection:
3 of 45 (6.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

zip 644b2bc164fb1118f399abd11f3e717491ae55560c042da604a9b784fc04c1f2

(this sample)

  
Delivery method
Distributed via web download

Comments