🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84b980fe26979262acd02db2695a978d79b0adaf462d5dc4e2cea043af1a21a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 84b980fe26979262acd02db2695a978d79b0adaf462d5dc4e2cea043af1a21a0
SHA3-384 hash: 93cfca5555cb73c555bb971dd8820415dfadc79ab2085126ecfa9ec300c3cc375fc309d16116cd1d099b7196ffcd9490
SHA1 hash: 09a1b94d1ecfe778e4e2e8925b734d15dad5858d
MD5 hash: f4f4bbde78b8f44adfb1336586ab8422
humanhash: alanine-skylark-echo-xray
File name:presente_244.zip
Download: download sample
Signature Gozi
File size:1'996 bytes
First seen:2022-02-23 05:29:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9LpXu1DInNcDLVlA+8HvOFs6Lv1UYtvhCMj8ydk/:RpXu1knwYevOYtppj8Ak/
TLSH T139414A2106E92203E5B92B3C9448A799F660C40327EA179B3B2A0DF01A458E8F25B0C3
Reporter JAMESWT_WT
Tags:Gozi inps isfb ITA Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
384
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive mshta powershell
Threat name:
Script-WScript.Trojan.Ursnif
Status:
Malicious
First seen:
2022-02-23 05:30:12 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
12 of 43 (27.91%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://atomline.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments