🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0e1ec547efb4fc050806d414d9fead46a962aedcab05a983d29b0e87330b994. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: c0e1ec547efb4fc050806d414d9fead46a962aedcab05a983d29b0e87330b994
SHA3-384 hash: 1e029d222a808df4ba9f122f71aa7e9c65f12a341672af6f75d2e328e0c943509d2a0b71b3e4a43d3830453f93e81e2c
SHA1 hash: 6c709a772ed327270703511d0d4c88a3bdbcfb1b
MD5 hash: 2a1447202f7fa4b43a21f34a4f5caf46
humanhash: moon-bacon-march-carpet
File name:Fattura 2203-23_012.zip
Download: download sample
Signature Gozi
File size:1'992 bytes
First seen:2023-03-23 12:35:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:92yS+qkdUVBQywEie6spIgqSBfqPD64y7W2VKNkYcb9Jnl:HskdUVwv2IQBfqb6N71KKZb9Jl
TLSH T18941086EC98C229FD0380B35C3A10F28B44452088063E503B38B639E6C4D9F3912BC3A
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:EUROSPURGHI Gozi isfb Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Fattura 3568 2023-300935.js
File size:6'733 bytes
SHA256 hash: 51afb2195e409f524c23923934d79ff7178ac1f0667a67c4a38df650b2668e41
MD5 hash: e4eb34a511ba4c4cb3540b016d04719d
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Clean
File Type:
JS File
Payload URLs
URL
File name
https://google.com
JS File
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
sload
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2023-03-23 12:36:09 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
6 of 37 (16.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:yara_template

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments