🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96cac6fbdb9eae2dd02e93f9638cf19408f192eb669ba6eefe20963492dc18bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 96cac6fbdb9eae2dd02e93f9638cf19408f192eb669ba6eefe20963492dc18bf
SHA3-384 hash: faa1f092a64f3f710bc2f16b0e101e67cf4907c8eb1e522c52c3fe5bff410a1a2470747baf5f9083232230a958c5b109
SHA1 hash: fb2de2404bc012adeb922aa516de6210cbf9be46
MD5 hash: 13726a198bcab3f2970f675a0eb2bd20
humanhash: oregon-california-double-muppet
File name:dettagli122.hta
Download: download sample
Signature Gozi
File size:4'409 bytes
First seen:2022-04-06 14:49:27 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 96:Yr3IXFq6CdkhGONLQh11mEVaLsJzhIviTv9I7y5J5yZe5tKG7Mc:YUCKni1wSlgi7Go74c
TLSH T127917A99031FC9FCE613ACC889D95A43EBB68626467CEAC0CF70BEFA2411478D0F4458
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi hta isfb Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
817
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
Encrypted powershell cmdline option found
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
PowerShell case anomaly found
Sigma detected: Encoded IEX
Sigma detected: MSHTA Spawning Windows Shell
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious PowerShell Invocations - Specific
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: Windows Shell File Write to Suspicious Folder
Suspicious powershell command line found
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
Threat name:
Document-HTML.Trojan.Ursnif
Status:
Malicious
First seen:
2022-04-06 14:50:06 UTC
File Type:
Text (VBS)
AV detection:
3 of 42 (7.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://loginlines.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments