🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cdd893b24d5b2dd1fbeef6a31123b5f02c945b90f8aa7aafec171d73df9eebc8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: cdd893b24d5b2dd1fbeef6a31123b5f02c945b90f8aa7aafec171d73df9eebc8
SHA3-384 hash: 1e0248cfe179897430965c1998ba807eebfa658817bce9a4d2442db7056b106a682a632f9cca1a76ecd822883e7ad644
SHA1 hash: 65080f029ea651d17ef9e76c49c4b6d2bb08e6ad
MD5 hash: 9df73c0b854e05d8357c71ee6e0e4f5e
humanhash: thirteen-earth-white-winter
File name:1_202306482273259151.pdf
Download: download sample
Signature Gozi
File size:48'083 bytes
First seen:2023-06-21 08:30:38 UTC
Last seen:2023-06-21 09:02:31 UTC
File type: pdf
MIME type:application/pdf
ssdeep 768:fpf138yi6yqF0eBiCfR/SeUruiGM6WRpGMkW7SGBsOh3NTkixbUwqt+q67mhSdVV:fpf1MAyfeBiC1UrKMhRpwWnBh3NkiRUW
TLSH T11523D07AB649181CF88EC716D23E3B8C29ED722349CD2446905E6B4249C1C19FA9F6C2
Reporter JAMESWT_WT
Tags:agenziaentrate balkun-com Gozi ITA pdf Ursnif

Intelligence


File Origin
# of uploads :
3
# of downloads :
445
Origin country :
IT IT
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
1.6/10
Score Malicious:
16%
Score Benign:
84%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for domain / URL
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 891898 Sample: 1_202306482273259151.pdf Startdate: 21/06/2023 Architecture: WINDOWS Score: 48 26 Multi AV Scanner detection for domain / URL 2->26 6 chrome.exe 1 2->6         started        9 AcroRd32.exe 15 37 2->9         started        process3 dnsIp4 16 239.255.255.250 unknown Reserved 6->16 11 chrome.exe 6->11         started        14 RdrCEF.exe 59 9->14         started        process5 dnsIp6 18 balkun.com 5.42.199.52, 443, 49701, 49703 MIDYAIQ Iraq 11->18 20 accounts.google.com 142.251.36.237, 443, 49699 GOOGLEUS United States 11->20 24 3 other IPs or domains 11->24 22 192.168.2.1 unknown unknown 14->22
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments