🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e21f6b70a246e4c07cbbba6d43ce7d5c1d400359058d1dea802b1684f88b526. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA 8 File information Comments

SHA256 hash: 8e21f6b70a246e4c07cbbba6d43ce7d5c1d400359058d1dea802b1684f88b526
SHA3-384 hash: e831c7d9d4500fbd7be5ef2f2c16b2eeb1958f8cc4f2f85281d4a5f4b71114b905745f1dc2d46817755d24bd5ed8d17f
SHA1 hash: 216b91575639cb18f2153a17f1109643e8c3b6f2
MD5 hash: 364fe1b5add3c81d19be025fc1a38142
humanhash: twelve-asparagus-uniform-coffee
File name:attachment.zip
Download: download sample
Signature Gozi
File size:141'939 bytes
First seen:2022-10-20 12:25:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 758493
ssdeep 3072:pqY/ThXYR/uQ789LZgA041W2KjuPredEZpd56iCOlEMl9U6LN:pB9oRmMaCYsMrxyu1
TLSH T177D3124744CF2229794725DEFA3344076BE0A388EC6732A96861917FCDD72B9352278F
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:Gozi isfb pw 758493 Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
176
Origin country :
n/a
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:highlighted.cmd
File size:378 bytes
SHA256 hash: 9b1f31bdc9ae8596f6cbf32f213857d74aa0801caf8bcf2f3b23ac9efb0d8f29
MD5 hash: 5ba9ba2fdc982323061d2fa8977b73e2
MIME type:text/x-msdos-batch
Signature Gozi
File name:buggies.txt
File size:218'393 bytes
SHA256 hash: db86c041ab135347ea6c7dcd7acd658ef1d74039690bd754d0f31ef05ce8bf6b
MD5 hash: 51dddb40ac822a7b9aa35c7168e3e88e
MIME type:text/plain
Signature Gozi
File name:5353.lnk
File size:1'831 bytes
SHA256 hash: 3217a3d5115cd2aefb82497017ed391c9400be479e56b9a6aa0e40f66da8cdcb
MD5 hash: ab707348e10bb475ae3da7dbc3a3e791
MIME type:application/octet-stream
Signature Gozi
File name:reservations.3ds
File size:118'784 bytes
SHA256 hash: 4c0ccba038ff513555223a880da3760a974b0479fe6cf0e823f08774ecd0d9ba
MD5 hash: 17ddc738604a040176b85c80173c5090
MIME type:application/x-dosexec
Signature Gozi
File name:bray.png
File size:27'560 bytes
SHA256 hash: b3efcbd17ef6c03bd93e13cff7ca5ab9be0e70b72c409d62a3911af8939cf35f
MD5 hash: db8186958edb6e81844086af223e9ae0
MIME type:image/png
Signature Gozi
Vendor Threat Intelligence
Gathering data
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2022-10-20 13:27:27 UTC
File Type:
Binary (Archive)
AV detection:
3 of 42 (7.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:PassProtected_ZIP_ISO_file
Author:_jc
Description:Detects container formats commonly smuggled through password-protected zips
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious
Rule name:win_isfb_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.isfb.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments