🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd5df28ed212183d98dac2e785e7cb9703769871585b6702b0a975b0c307b874. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bd5df28ed212183d98dac2e785e7cb9703769871585b6702b0a975b0c307b874
SHA3-384 hash: d57b0f1d438cdb68e6a3ed359d494e90fa702c6547749bf688d74787d9d779ad877de19bc785fccfc763513c894a4e04
SHA1 hash: 924ad5b20dcdeef52c47e497e42726b2d4019244
MD5 hash: e17daca1c951e357d383fa9062cddcb6
humanhash: lima-happy-wyoming-steak
File name:8_IT05953829442_90_26042023_029000.pdf
Download: download sample
Signature Gozi
File size:179'726 bytes
First seen:2023-04-28 06:30:52 UTC
Last seen:2023-04-28 06:34:52 UTC
File type: pdf
MIME type:application/pdf
ssdeep 3072:Olv1U1qS1maNhyWyLrbYfEZwcYqJmaA4jfntQ1aIC7GzS4e+q5EOcmmMsb8D+1VT:OZ1uQaDlyLr2AX7A4jtt7aW4CpkADQ
TLSH T1A004CE471A58E395C01C09E4AC471EE82E0B2719E9852EFB741E4F9F3F41A736CDA46E
Reporter JAMESWT_WT
Tags:DhlCredit Gozi pdf Ursnif

Intelligence


File Origin
# of uploads :
2
# of downloads :
412
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
7/10
Score Malicious:
8%
Score Benign:
92%
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Document-PDF.Trojan.Ursinf
Status:
Malicious
First seen:
2023-04-27 10:32:49 UTC
File Type:
Document
Extracted files:
8
AV detection:
4 of 37 (10.81%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments