MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c99f4de75e3c6fe98d6fbbcd0a7dbf45e8c7539ec8dc77ce86cea2cfaf822b6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: c99f4de75e3c6fe98d6fbbcd0a7dbf45e8c7539ec8dc77ce86cea2cfaf822b6a
SHA3-384 hash: f56db9bda066f319f39c45cdad69789df5c0194c0188c07c80dcf34b9247f906eb320bb957222c5614f875025158fdf1
SHA1 hash: 5409dcfd982f3bd941247cbf2962a6fa00c0c38d
MD5 hash: c71cbf60e9013deda6bea0387b909db4
humanhash: blue-bluebird-freddie-floor
File name:AgenziaEntrate_decoded.js
Download: download sample
Signature Gozi
File size:6'118 bytes
First seen:2023-03-19 05:46:50 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/html
ssdeep 96:ma3aQGuIzMTPPvQCCRoJZ+ArgJC4RcezE9MBfB/MIra1nIurD1nTty4lj1PRWl06:ma3aBuIYTPPvQ1OZ+GMC9e6MVo1nL1nA
TLSH T1E8C1D693AA7246F01133419FC1ABBB24B93016B76C545C301D19E9187D76E9F826DEC8
Reporter 0xToxin
Tags:7709 Gozi js

Intelligence


File Origin
# of uploads :
1
# of downloads :
246
Origin country :
IL IL
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
2 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MalScript_Tricks
Author:@bartblaze
Description:Identifies tricks often seen in malicious scripts such as moving the window off-screen or resizing it to zero.
Rule name:QbotStuff
Author:anonymous

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments