MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93fa29d1909eabc982ded10dd753233618f68f0c3e769deb26eea24c5af715b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 93fa29d1909eabc982ded10dd753233618f68f0c3e769deb26eea24c5af715b4
SHA3-384 hash: ffa933cc4f95023bec199ba9924dc4be5aca3be542907045f8aaa260dca78418a59aa0897fe1faa0f7d4852777133c36
SHA1 hash: 3ed0d5413d184fa059ebef7f916be9b684e09dba
MD5 hash: 77c29f8cb55b57011f8f676a23956d2b
humanhash: yellow-bakerloo-georgia-colorado
File name:main.hta
Download: download sample
Signature Gozi
File size:2'598 bytes
First seen:2021-03-16 06:03:30 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 48:Uwi3T1yYaY2dFE+X/nLubwvY3CYFuNfInaI5u0G9:bi3T1NRIE+PLukASY0gO
TLSH D051C8EBFCA363A49896084B6C6CF1A63430A6122644D43BC980DD5CBE527E4CE63E91
Reporter JAMESWT_WT
Tags:pw6564234 Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
181
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2021-03-16 06:04:06 UTC
File Type:
Text (HTML)
Extracted files:
3
AV detection:
3 of 46 (6.52%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments