🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3ba7f09e554d775d00fa52b4e1eb2159fcd87682cc7bccd4a116620b5f55dcb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: b3ba7f09e554d775d00fa52b4e1eb2159fcd87682cc7bccd4a116620b5f55dcb
SHA3-384 hash: a9e222a281e449a800d70e52dffef95cb61a4ff1526ebe7220304389efc59c892bb04a4d1941abc5e96569b26e2a3d3b
SHA1 hash: 5872dfc3059d5bd18226819d8a11097097e0bfe2
MD5 hash: 0c048ed07c5754f4efa55e2f42a9e9cc
humanhash: juliet-oranges-coffee-snake
File name:comunicazione(1).pdf
Download: download sample
Signature Gozi
File size:60'187 bytes
First seen:2023-06-21 10:57:19 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:mY/fBo1tl5HIPgQbymbPZL12nuyyctlSz3kD:mY/Zo1v5ogQby8Z5P8iq
TLSH T18443E1BAE2B9946CD5C71C21DE2B35C1DFCCF2A28AC571C614BB5DBA4418C6CDE801DA
Reporter JAMESWT_WT
Tags:agenziaentrate balkun-com civis Gozi ITA pdf Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
484
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
1.8/10
Score Malicious:
18%
Score Benign:
82%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for domain / URL
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 891970 Sample: comunicazione(1).pdf Startdate: 21/06/2023 Architecture: WINDOWS Score: 48 26 Multi AV Scanner detection for domain / URL 2->26 6 chrome.exe 1 2->6         started        9 AcroRd32.exe 15 37 2->9         started        process3 dnsIp4 16 239.255.255.250 unknown Reserved 6->16 11 chrome.exe 6->11         started        14 RdrCEF.exe 61 9->14         started        process5 dnsIp6 18 balkun.com 5.42.199.52, 443, 49694, 49699 MIDYAIQ Iraq 11->18 20 accounts.google.com 142.251.36.237, 443, 49696 GOOGLEUS United States 11->20 24 3 other IPs or domains 11->24 22 192.168.2.1 unknown unknown 14->22
Threat name:
Document-PDF.Trojan.Ursnif
Status:
Malicious
First seen:
2023-06-21 10:11:03 UTC
File Type:
Document
Extracted files:
8
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments