🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73bc302906aef2544f8508fea3b9fa2e0a148ee4466872ba9e74ef23978c80bb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 73bc302906aef2544f8508fea3b9fa2e0a148ee4466872ba9e74ef23978c80bb
SHA3-384 hash: 06fee3e7ba37fba6faff045863c43672a5cdbd4844a0d537b690ea4e9092e946929d05842d23100eeefd07b49d818e27
SHA1 hash: a8d31bd54f70951b8dc61695d357f36d3fd23397
MD5 hash: 70e2098acfdc24f9812ce9abe9d5ba86
humanhash: table-west-montana-apart
File name:1_IT0_05_25_2023_01_21314.js
Download: download sample
Signature Gozi
File size:41'149 bytes
First seen:2023-05-25 16:50:11 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:Yn4dQJxwT4mBPKY7QZqDXSTKL0gskkYiDQBymAc7X7:YnbxAxBiSxDXEKL0//YymAu7
TLSH T10803A5CE3F81F8309762A477AA4FE0E9ED1E6C51658841EEF625BC54F5E821DE233418
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi isfb js Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
352
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
nemucod powercat virus
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
68 / 100
Signature
JavaScript source code contains call to eval() to check own source code (likely for evading instrumentation)
JavaScript source code contains functionality to generate code involving HTTP requests or file downloads
JScript performs obfuscated calls to suspicious functions
Potential obfuscated javascript found
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments