🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d025ee7d2be36308e13ea988e3e15ab0e687972624ff88db059d472df7f46253. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: d025ee7d2be36308e13ea988e3e15ab0e687972624ff88db059d472df7f46253
SHA3-384 hash: a97a16681e4905c60b992172d6524e9cb02a904e7fe683ca1ffd67b545decbe657e505abb2e12febf317a272bf45b13e
SHA1 hash: 2d29989d7c335af3036c22da4fb433007765e382
MD5 hash: e8b5043f0f263f7f66bdee786904268b
humanhash: sierra-black-hamper-saturn
File name:printouts of outstanding as of 06062023.js
Download: download sample
Signature Gozi
File size:105'585 bytes
First seen:2023-06-06 18:42:08 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 1536:ib5ox+pXEhuiykvoCcyGH33vI7n8GwKQ1JIYFJSJ9EYtgHHVCD2uU9tIsIfiQ:85o8tnQFBQnQWV4FPz
TLSH T1D0A3FD84060A2ADD409C13B5E48C3D5970953AFEED9A9D4FEBBC078D018EDCB5E5372A
Reporter fr0s7_
Tags:Gozi js mikehp-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
334
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Script-JS.Downloader.Nemucod
Status:
Malicious
First seen:
2023-06-06 18:43:06 UTC
File Type:
Text (JavaScript)
AV detection:
8 of 36 (22.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments