🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 baee00cebd91c745753ee59d3abd4b655f4e90231a61c04eecf3f299297b936a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: baee00cebd91c745753ee59d3abd4b655f4e90231a61c04eecf3f299297b936a
SHA3-384 hash: e40b18efe2d63ac40c9ec13256316af765bb17fe57f6718d2fcebaba32f81fea544c384902952a98e5f44fd80250ef41
SHA1 hash: 4093042f5b36b8950d77c5a4a8221d08b2fcede5
MD5 hash: abc14693c2e9de73e05e4fd3b2d0985b
humanhash: don-nevada-grey-three
File name:comun197.zip
Download: download sample
Signature Gozi
File size:6'893 bytes
First seen:2022-03-17 12:27:44 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:Z1BmnVrdmChmrCJkVRZwwoaWIejt0jM5yzvNr1IaMDN5Abg9:fByhm7uxa7jQyhbMp5Abw
TLSH T121E17ED77D839E2DD80301B193F26209E67CD34CA826356DBE2DD63E95A2254D1076C9
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi isfb Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
477
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mshta
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Download via BitsAdmin
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments