🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 690e944d5620ca62def957865ee4d52d6a3ff155d1ef3ff6fd59b673ef9f8735. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 690e944d5620ca62def957865ee4d52d6a3ff155d1ef3ff6fd59b673ef9f8735
SHA3-384 hash: 8d8566ddc69f01b96ecadb13638c242c5f48f74290cf340ec8edd435e0ebf5264fb48e848a0678202ef8f2d467f1e8a5
SHA1 hash: 7ddd0098e59782da5061a6f0d97c893a0b9334f7
MD5 hash: aa02bbc9809639caf55768699c06bb9d
humanhash: hydrogen-purple-apart-oklahoma
File name:Inv_1384_from_BBP Accounting_625182_12970.pdf
Download: download sample
Signature Gozi
File size:38'019 bytes
First seen:2023-10-10 08:30:45 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 768:hBQoSQ3Aid+woTuNDIZehmb4FYzolkOjA0L/il2yoXWLOnI+X2arJfx8f:3Qo7+w61ehmbjzek0Ol2yozIxarNm
TLSH T10F03C04AA694ACEAC4D545B3C43B3942B778B13306C4B89D6C6C70CB3F0A975D9C6AC3
Reporter 0x_malw_research
Tags:91-212-166-74 Gozi intuit pdf Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
522
Origin country :
GB GB
Vendor Threat Intelligence
Gathering data
Label:
Benign
Suspicious Score:
2.3/10
Score Malicious:
23%
Score Benign:
77%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for domain / URL
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2023-10-10 08:31:05 UTC
File Type:
Document
Extracted files:
6
AV detection:
12 of 38 (31.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Gozi

pdf 690e944d5620ca62def957865ee4d52d6a3ff155d1ef3ff6fd59b673ef9f8735

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments