🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4e9649da2711297e6859caa2843d0b6f2afc2519cce352afe71d09d2766040d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c4e9649da2711297e6859caa2843d0b6f2afc2519cce352afe71d09d2766040d
SHA3-384 hash: 5874d0dab8c95bac87586d1054bf0d0f57dda4ad6fe0b251e695710426f3c98543ef1ad019fd202508e63f573c07f518
SHA1 hash: 27c49fa3c64f116cc24cba865aa7a3de2529478a
MD5 hash: 0dc4ae4265ba00d462033eb384117f94
humanhash: mango-hamper-march-mike
File name:Fattura_01493017.pdf
Download: download sample
Signature Gozi
File size:50'134 bytes
First seen:2023-06-01 06:59:32 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:TdwZ7yHCKBs7CofGkm5tMn/VEgp1U58vLMsrQg+oN7B:pwZ7yiKBmCoOk8Mn/V168vgs8g+4B
TLSH T15133C0B9A259246FD086C5F26E2435861B9FF12369D57413387C895E3FC4E2CFA10BB1
Reporter JAMESWT_WT
Tags:brt Gozi pdf Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
462
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Malicious
Suspicious Score:
5.7/10
Score Malicious:
58%
Score Benign:
42%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Trojan.Ursnif
Status:
Malicious
First seen:
2023-05-31 09:54:38 UTC
File Type:
Document
Extracted files:
21
AV detection:
3 of 37 (8.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments