🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aef3eaec34ae2ba173d06dc5ab4028955d8e6e95c967493140edb3d97fb3d077. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: aef3eaec34ae2ba173d06dc5ab4028955d8e6e95c967493140edb3d97fb3d077
SHA3-384 hash: 82f13b8354158be8151b324d17334b30adc0e25cfc25625e40f3d0f806b1e0522871be1fed2e425e31a36c51e5f886a4
SHA1 hash: ec7b5c7d892419e60f10de4e708f5f2aa6a7ce11
MD5 hash: c83097edf4c10cfd387743a74bf20abb
humanhash: football-high-zebra-paris
File name:Agenzia_E(1).zip
Download: download sample
Signature Gozi
File size:5'206 bytes
First seen:2023-02-10 06:11:17 UTC
Last seen:2023-02-10 06:11:41 UTC
File type: zip
MIME type:application/zip
ssdeep 96:iTTjWVg/aycnuRb1HXDx4JiU4I+acXnxbY77hTalL+lO4WzcRu2REROR/D:2GVEaduXXW72aUx0HhTalL+nWzau2yR6
TLSH T1C1B18DD6E880D4BFFE44F17CB9306D2CDD9ED0E6356AD05280A6C9100C857625EEB40F
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Agenzia_E.hta
File size:7'208 bytes
SHA256 hash: e656c7f8cba012cb4db32513be31d0a79db61b7ebff4a82e93921638e6e2b377
MD5 hash: 2b0d4ccd7c0c123a59c60207d5f2d3bf
MIME type:application/octet-stream
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
http://www.protware.com
HTA File
Threat name:
Document-HTML.Trojan.Ursnif
Status:
Suspicious
First seen:
2023-02-10 06:02:51 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
5 of 26 (19.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:QbotStuff
Author:anonymous

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gozi

zip aef3eaec34ae2ba173d06dc5ab4028955d8e6e95c967493140edb3d97fb3d077

(this sample)

  
Delivery method
Distributed via web download

Comments