🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a6e1e3dafbbdb2a746d5f8ced43373d74fdaa1354ec7295d74a77fcbe9562f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7a6e1e3dafbbdb2a746d5f8ced43373d74fdaa1354ec7295d74a77fcbe9562f2
SHA3-384 hash: e09269bcb85db8d72bab3a819c68cfed3fc2aa19483b05868d048a979d7b1befdb889aef02598a5e995ad25f58d24d0b
SHA1 hash: dd536317c8260eb8c18ad7a0d7a651fc5b17959b
MD5 hash: 4bd53e472dd5e54221d91a6937c8a275
humanhash: spring-jupiter-kansas-pasta
File name:gov95.hta
Download: download sample
Signature Gozi
File size:10'144 bytes
First seen:2022-03-08 07:51:00 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:application/octet-stream
ssdeep 192:1YVwfUdXXkZCkcFMRn6cKUh/ig71XgbBxsmxxiMBXBRv06M8oe3dJWsebT+2:1YKsf7qRn+i6UdgNxsqjRv0FmUbq2
TLSH T14A22289EB36BD448975314E7E8661F0F5200CFEBFFF8D684B05847822828F5A690096D
Reporter JAMESWT_WT
Tags:Gozi hta isfb mise Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
285
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script.Trojan.Ursnif
Status:
Suspicious
First seen:
2022-03-08 07:51:11 UTC
File Type:
Binary
AV detection:
11 of 27 (40.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments