🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac89dbce110db24016f8342e133962aa0bcda641bc14fc489bbe20c1070736b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: ac89dbce110db24016f8342e133962aa0bcda641bc14fc489bbe20c1070736b6
SHA3-384 hash: 94a567d31f3f7754297cc6749762eb569d30a8186bf267cf2091536873549f440e93e0e5a576c17f2917d3b12fd77000
SHA1 hash: 36118902e77d431ddb7f5ad8ed83f7d694121728
MD5 hash: 4a17a81693a9b4dcd1466bc71eb08016
humanhash: thirteen-black-eleven-fillet
File name:Disposizioni831.zip
Download: download sample
Signature Gozi
File size:343 bytes
First seen:2023-10-03 03:00:39 UTC
Last seen:2023-10-03 03:38:10 UTC
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: agenzia2023
ssdeep 6:5j+tg0mVrixmsfic1L1JxSiXwStysIq99wpaCjYySBtqknRu+lL:5jqsVrYmsKc1RJJweysIq99Ipjcq1aL
TLSH T1A4E07D25758B2DA1E441DFFA74CA87710271F52402A462DAC69934357FF274E18B1D81
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi pw-Agenzia2023 Ursnif zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
133
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Disposizioni.url
File size:192 bytes
SHA256 hash: 8bb04ebea49b92e090b777efedfa44c8aa881a5531a0791f7f2404d0d50f9963
MD5 hash: 52aa02b4f67f2f504fcb991e6d094e58
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Methodology_Suspicious_Shortcut_SMB_URL
Author:@itsreallynick (Nick Carr), @QW5kcmV3 (Andrew Thompson)
Description:Detects remote SMB path for .URL persistence
Reference:https://twitter.com/cglyer/status/1176184798248919044
Rule name:SUSP_URL_SMB_exe
Author:abuse.ch
Description:Detects suspicious internet shortcuts linking an executable on an SMB share

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments