🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4d822da39021d4dccf1f4fdee531094e3334d4591a88bfca71829e02ca93f37. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: b4d822da39021d4dccf1f4fdee531094e3334d4591a88bfca71829e02ca93f37
SHA3-384 hash: 7907aec6b66c88853812bb1e511512a5cc892b9a8c963f03db940c24a0644ccde49333f3ad8540d2e692e91d80478341
SHA1 hash: bf66b5824c12212e891e6506d475aa7aa6f26e19
MD5 hash: 63dfab731a8ceccf055c3af6e327be7f
humanhash: zulu-august-music-xray
File name:Inv_143469_1199717329697.pdf
Download: download sample
Signature Gozi
File size:43'711 bytes
First seen:2023-10-13 07:03:30 UTC
Last seen:2023-10-13 07:03:41 UTC
File type: pdf
MIME type:application/pdf
ssdeep 768:Ox3LyiWooKYLTj38meNxMDABL1X8aNnNErX8OrHPpcnTwx7qHZ7T2VKzCM2:OxnXW6kDUarsOrxcTYcZc5F
TLSH T1E513AF07D0285646CA8D87B4BE091D9C598D7BB9B3D235EA347E4FCE3B14B03BD64069
Reporter JAMESWT_WT
Tags:Gozi pdf qusbec-com Ursnif

Intelligence


File Origin
# of uploads :
2
# of downloads :
561
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
7/10
Score Malicious:
8%
Score Benign:
92%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Ursnif
Status:
Malicious
First seen:
2023-10-12 15:52:43 UTC
File Type:
Document
Extracted files:
6
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments