🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cec19d81223baaee1c6c73d5760940bd0ab79d55adb043b63cfa37d08b96f8cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: cec19d81223baaee1c6c73d5760940bd0ab79d55adb043b63cfa37d08b96f8cc
SHA3-384 hash: 8fee2e22b7446fb2b96d63322a41a4025ee00ee14266581f07c070c837f2645d6648ffd57f42508e2467c9f9b953435c
SHA1 hash: de9d1cbcdf826876553103028a00beb0f3362a07
MD5 hash: 101c6f454993a892b238a6fcdbc81f63
humanhash: foxtrot-glucose-nitrogen-arizona
File name:Invoice_09142023_5743322235.zip
Download: download sample
Signature Gozi
File size:447'716 bytes
First seen:2023-09-15 04:56:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:/AkX2gX/j9CVXN6zocE8gFWPmyjlE6rvwncY/j8U0i8UZnJX+S0SiFey:/AsiMFiWPJkX/jAibZJX+YQey
TLSH T12794231662F717F387ADEA6CA44BE6A61E3467F14F304821D3F4CF806B5D299031A4B6
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter JAMESWT_WT
Tags:goamiev-com Gozi intuit zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Inv_09142023_129272_307806.js
File size:1'300'550 bytes
SHA256 hash: f3489b0781a345b583a77439f980f65df1194f7effed341dcb9cd7e0a6ef3605
MD5 hash: f04c2cdca76878b53ee26592ad96db68
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Payload URLs
URL
File name
http://kb.mozillazine.org/Clipboard.autocopy
JS File
Threat name:
Script-JS.Downloader.Heuristic
Status:
Malicious
First seen:
2023-09-15 04:54:59 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
4 of 37 (10.81%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Script User-Agent
Uses Task Scheduler COM API
Drops file in System32 directory
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments