🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bdea9a6d29b232bc69e3502ee4710f0c5e99c2d0ea996624545d39760a104750. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: bdea9a6d29b232bc69e3502ee4710f0c5e99c2d0ea996624545d39760a104750
SHA3-384 hash: d94d4b3ee63c863882575340644ecc8ff9a07a044b5cc0dec8f7a678e4e8d305c8f3820045b46f8f661b5fa8ace967d7
SHA1 hash: f031a4c279c853e79eb67f6b52329ebaf4ccf8d8
MD5 hash: 216119daf20d8898a3ba051f1d8e5d9b
humanhash: quebec-illinois-two-football
File name:documento9.js
Download: download sample
Signature Gozi
File size:33'531 bytes
First seen:2023-03-23 13:12:14 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:WGu+++I6frB7NyYHboi+P/0fQ4DV3KEp3KEW3KEL3KEf3KEo3KEIv3:U6f/yYHbUX0fQA3pp3pW3pL3pf3po3pk
TLSH T15EE2C06B1C43DBD9E1E60B0531EA26727F44E660851BBC6316392C5217B2BF970FE81B
Reporter JAMESWT_WT
Tags:EUROSPURGHI Gozi js js2 Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
254
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
nemucod powercat sload virus
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
80 / 100
Signature
Creates processes via WMI
JScript performs obfuscated calls to suspicious functions
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sample has a suspicious name (potential lure to open the executable)
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies system certificate store
Blocklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments