🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d96bd7bdb83932a81c02ceb4aff61ae804a542b40f45ec5fe3d0ad2c8492d4fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d96bd7bdb83932a81c02ceb4aff61ae804a542b40f45ec5fe3d0ad2c8492d4fe
SHA3-384 hash: c6197ce512130f31a9856d599a04ec35c119a5e55df55f36181bddbd19843f756966e40bf9adb19280c060192ae45a00
SHA1 hash: 44025232b042dc222963f319f49aa643c221d3af
MD5 hash: 82b700b321f4a07c0c0d4a7c368b2bab
humanhash: seventeen-south-pennsylvania-missouri
File name:Invoice_details.pdf
Download: download sample
Signature Gozi
File size:34'843 bytes
First seen:2023-07-18 16:31:33 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 768:yjIReeOSxVaD/oc3onoO8fVGLisOwVcN6imgSCmedGQQXDllTj:gfVGLiJX4imgSCmSi5N
TLSH T147F2BE14C59638DCE11223D21B6D789F266EB136B1C941C13EEECFDB4340EAA9943397
Reporter proxylife
Tags:20000 Gozi pdf Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
487
Origin country :
US US
Vendor Threat Intelligence
Label:
Malicious
Suspicious Score:
6.4/10
Score Malicious:
65%
Score Benign:
35%
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl
Score:
52 / 100
Signature
Downloads suspicious files via Chrome
Potential malicious clickable URLs found in PDF
Suspicious execution chain found
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1275331 Sample: Invoice_details.pdf Startdate: 18/07/2023 Architecture: WINDOWS Score: 52 81 Potential malicious clickable URLs found in PDF 2->81 83 Downloads suspicious files via Chrome 2->83 85 Suspicious execution chain found 2->85 10 chrome.exe 8 2->10         started        14 AcroRd32.exe 15 37 2->14         started        process3 dnsIp4 71 192.168.2.3 unknown unknown 10->71 73 239.255.255.250 unknown Reserved 10->73 59 C:\Users\user\...\Invoice_Details.zip (copy), Zip 10->59 dropped 16 unarchiver.exe 4 10->16         started        18 chrome.exe 10->18         started        21 RdrCEF.exe 63 14->21         started        file5 process6 dnsIp7 23 cmd.exe 2 2 16->23         started        25 7za.exe 2 16->25         started        61 www.google.com 172.217.168.68, 443, 49698, 49718 GOOGLEUS United States 18->61 63 accounts.google.com 172.217.168.77, 443, 49690 GOOGLEUS United States 18->63 67 7 other IPs or domains 18->67 65 192.168.2.1 unknown unknown 21->65 process8 process9 27 wscript.exe 1 23->27         started        29 conhost.exe 23->29         started        31 conhost.exe 25->31         started        process10 33 cmd.exe 1 27->33         started        35 curl.exe 1 27->35         started        38 cmd.exe 1 27->38         started        40 7 other processes 27->40 dnsIp11 42 curl.exe 2 33->42         started        45 conhost.exe 33->45         started        69 www.7-zip.org 49.12.202.237, 443, 49707 HETZNER-ASDE Germany 35->69 47 conhost.exe 35->47         started        49 conhost.exe 38->49         started        51 conhost.exe 40->51         started        53 conhost.exe 40->53         started        55 conhost.exe 40->55         started        57 3 other processes 40->57 process12 dnsIp13 75 cajaminoretino.site 104.21.12.177, 49701, 80 CLOUDFLARENETUS United States 42->75 77 188.114.96.7, 443, 49704 CLOUDFLARENETUS European Union 42->77 79 127.0.0.1 unknown unknown 42->79
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments