🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7f0b16dfc95c81abfeee0982b7039c4964f8a871f2f7a0be13c294a89c00d5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b7f0b16dfc95c81abfeee0982b7039c4964f8a871f2f7a0be13c294a89c00d5d
SHA3-384 hash: ffa03a60e4b2e5b3b37df426bd132565ac1b90329b0e48a5fc55d86ae0ee3db1c0a878a74c5363589c4179d6c27afb99
SHA1 hash: 1825e02ec4659d7969dc262d76549b424018ea2a
MD5 hash: 7aa6f788234537837a9fb5ade2a0dad7
humanhash: cardinal-mobile-muppet-oregon
File name:Fattura 3601 2023-3000440.pdf
Download: download sample
Signature Gozi
File size:131'841 bytes
First seen:2023-03-23 14:33:59 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:3plLUnJS0g5u6jejkszxSxhCtY30JvyizUW6tox5nO:3plLKF6jeTmmaZHox5O
TLSH T140D3E10C7695DC0BE9F94632D468EC92932AB7F287FF55157C9EC412F723EA1AC92201
Reporter JAMESWT_WT
Tags:EUROSPURGHI Gozi isfb pdf Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
440
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
9/10
Score Malicious:
9%
Score Benign:
91%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Antivirus detection for URL or domain
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 833350 Sample: Fattura_3601_2023-3000440.pdf Startdate: 23/03/2023 Architecture: WINDOWS Score: 48 30 Antivirus detection for URL or domain 2->30 6 chrome.exe 13 1 2->6         started        9 AcroRd32.exe 15 37 2->9         started        11 chrome.exe 2->11         started        process3 dnsIp4 20 239.255.255.250 unknown Reserved 6->20 13 chrome.exe 6->13         started        16 RdrCEF.exe 63 9->16         started        18 chrome.exe 11->18         started        process5 dnsIp6 22 accounts.google.com 142.250.203.109, 443, 49681 GOOGLEUS United States 13->22 24 clients.l.google.com 142.250.203.110, 443, 49682 GOOGLEUS United States 13->24 28 3 other IPs or domains 13->28 26 192.168.2.1 unknown unknown 16->26
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments