🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97aa441e8b104661a633d705fe16af3ae24dd645e8ae96c1be21eae69d353092. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 97aa441e8b104661a633d705fe16af3ae24dd645e8ae96c1be21eae69d353092
SHA3-384 hash: b673f2305761c33e9e7a8072ea2a7f9a39edc13571f05cf94f82feb287cdbc0d9d7e8f11d2abd41b46623f1206935eb7
SHA1 hash: 79cc7c67519d2a73f8dcfdb73c5268f1997e924b
MD5 hash: 3912f44df67d43a47c51c62e5fff2701
humanhash: tennessee-edward-crazy-network
File name:1 Total New Invoices - Wednesday May 17 2023.zip
Download: download sample
Signature Gozi
File size:20'591 bytes
First seen:2023-05-19 09:45:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:LGUFwhF+xcfbVndEUiKyDzpgwiqgRHlV0hkeYZcb48gpzO6:vGhA0DypiHT0htYZkGi6
TLSH T18A92E17787129C85E61FEBAC17BD586135DA3403F9030F98B94020623AE90D7F793A6B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:Gozi vipbeed-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:1 Total New Invoices - Wednesday May 17 2023_1066.js
File size:76'863 bytes
SHA256 hash: 21c2aa44f853b35566bb5fbe52a38d921a8f30a6a23f3eab118e8707ebb46d97
MD5 hash: f4756e8439833f67c6d62cb06b7817fe
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Clean
File Type:
JS File
Payload URLs
URL
File name
https://bl
JS File
Verdict:
Malicious
Threat level:
  10/10
Confidence:
88%
Tags:
obfuscated
Threat name:
Binary.Malware.Generic
Status:
Suspicious
First seen:
2023-05-18 19:53:26 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments