🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 653c934bb9ae7e3feb234fc932f22f8e0f00b14cd0e2c8ab2e79a51e25459150. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 653c934bb9ae7e3feb234fc932f22f8e0f00b14cd0e2c8ab2e79a51e25459150
SHA3-384 hash: ee906c11aab4f46a051d746d71dd1fd13205976badc14ad5401c8ca460ff48fa13708e77fb78a901c430398f38865a4b
SHA1 hash: 3f3f94bab653b519832c45286aa74995c72c2dd8
MD5 hash: 6b54bafffe21e24f0b4f07790fee16a9
humanhash: sweet-dakota-oklahoma-fourteen
File name:Agenzia_30.vbe
Download: download sample
Signature Gozi
File size:246 bytes
First seen:2022-02-10 10:21:49 UTC
Last seen:Never
File type:Visual Basic Script (vbe) vbe
MIME type:application/octet-stream
ssdeep 6:GJgK+Jq74zXpiAAWAwdHAHKV8qENB/TU2epWx5n:GJgK+J1iAAWAoHr7EbwbpWTn
TLSH T186D095476479401C141D45557F11B4C59C11FBC500F474DD5757597D4859D87F009F94
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi Ursnif vbe

Intelligence


File Origin
# of uploads :
1
# of downloads :
335
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-WScript.Downloader.Nemucod
Status:
Malicious
First seen:
2022-02-10 10:22:09 UTC
File Type:
Binary
Extracted files:
1
AV detection:
10 of 28 (35.71%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments