🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2e38dcde349a45f7b292878dd74ce57f1885a9f2cc9c0d33a30f1cb78cd6d57. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b2e38dcde349a45f7b292878dd74ce57f1885a9f2cc9c0d33a30f1cb78cd6d57
SHA3-384 hash: a1c09cda2e213383564e27054d7ab095577728aa9aa76929a7568107454af2db7afb107e5c8e2f72cbcc1a5a54d845b7
SHA1 hash: b9b588d217cb938dfbb7f39d4fcc168ac32cba26
MD5 hash: 7ba6929ac66130a24c32a947616ea57d
humanhash: equal-delta-florida-salami
File name:documentaz_819.hta
Download: download sample
Signature Gozi
File size:4'149 bytes
First seen:2022-02-22 09:38:57 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 96:IHqstdfgpN2g2bcl/VRMN8R3kw/PAM+TVZZuSKm8RIFlTajM:Cr2x2bcl/VyqRTTqZYIFZ
TLSH T1D381C499074FCAFDF667ACC4C5D95A03EBB58626062CE6C0CF607EFA2504978E4F1858
Reporter JAMESWT_WT
Tags:Gozi hta inps Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
331
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-WScript.Trojan.Ursnif
Status:
Malicious
First seen:
2022-02-22 09:39:08 UTC
File Type:
Text (VBS)
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments