🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aab8df87a73b764c730a21d70e8f689a3c8fa1c760eaccd482e5fc4132798ac5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA 6 File information Comments

SHA256 hash: aab8df87a73b764c730a21d70e8f689a3c8fa1c760eaccd482e5fc4132798ac5
SHA3-384 hash: 44bfe4f269d86223e3a13faeb0c481fc423194a64d4a76722f7a65d20f3f577cf1156bea85b09b438e2c05356cdb6dc1
SHA1 hash: 2b4e3a273d568550e45aadec125b980d8eeff3bf
MD5 hash: 1201deb725d512a6c0e2b70799115be5
humanhash: vermont-yankee-five-thirteen
File name:fc83217e920d36d6b322812d129919b67c7d241a7c77111ddf24d49b4c1b8cec.zip
Download: download sample
Signature Gozi
File size:47'404 bytes
First seen:2023-01-31 23:42:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 768:R30a8E0uM/PNyqUpQnyqufd79Lq3BmOpNJa1e7yCo40tzgI3UP6F2mbjDov10nkv:RkaTfQXsfWBbpNJaU2C46t6FbC10nkIq
TLSH T1652302389BA16726E213AFF408BB426279208C5591AB9404D970F386F479EFF6770E58
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter atomiczsec
Tags:Gozi zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
n/a
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:comunicazione.xls
File size:76'800 bytes
SHA256 hash: fc83217e920d36d6b322812d129919b67c7d241a7c77111ddf24d49b4c1b8cec
MD5 hash: fe126e58d4aa4f8591254b0ec18bad59
MIME type:application/vnd.ms-excel
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive macros rundll32 ursnif
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB
Rule name:TA505_Maldoc_21Nov_2
Author:Arkbird_SOLG
Description:invitation (1).xls
Reference:https://twitter.com/58_158_177_102/status/1197432303057637377

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments