🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5001864f14cc431f1c19a4438e647ab1ddae1bb41e13ea1692b7790688aa723. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d5001864f14cc431f1c19a4438e647ab1ddae1bb41e13ea1692b7790688aa723
SHA3-384 hash: f787c080ad0e369e58b6d865b61f52b9689bddfdb4316fd75a147d737788dce76347fe5ab8ffc520b70806311fbdbc7f
SHA1 hash: 4ee75178c0e471c57a0eda488f0b6eb10b6ec6d0
MD5 hash: 7da4b8deb51cd7eb54624826fa2b65df
humanhash: triple-tennis-ohio-seventeen
File name:Documento_17.zip
Download: download sample
Signature Gozi
File size:404 bytes
First seen:2022-02-10 10:33:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12:5jJHOZB6BMnAfsjjCMO1cHRmb7/QzujI+tk1Jaf:9xCnAmjxScxmbzlRtky
TLSH T1F1E0610C130B0307E05E9AFCE55F1A149D24DC98D8F87697E00885FD2EE15191D3262B
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
346
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-WScript.Downloader.Nemucod
Status:
Malicious
First seen:
2022-02-10 10:34:07 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
13 of 27 (48.15%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments