🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc70cecd5c5839b63d755e1dfcdbe6e0db6aedb694635c5600aa50cc15e0c11e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: dc70cecd5c5839b63d755e1dfcdbe6e0db6aedb694635c5600aa50cc15e0c11e
SHA3-384 hash: 6859b070ffbe823ec8a12ba610122710d5319b1288974f394a15778056ffffed6098fbdcf3fa07fd36fb31337c1bcbf6
SHA1 hash: c71bc654c8e9aa7fc293ed856137578746f0cdaf
MD5 hash: ddaa6c813f04fcd20d49104bceeea109
humanhash: ceiling-colorado-blossom-burger
File name:RIMESSA_CASSEGNI03016023.zip
Download: download sample
Signature Gozi
File size:4'440'838 bytes
First seen:2023-03-16 09:44:20 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 98304:iAXLIMrxuPRytxIeYhj2IlPdnKHsNU6aflg2GYmhOqh+L+:ZgoxY2qgH6zOqh
TLSH T1782633126A99043D796D567C807B838BB9F691CB36B33BD45D0D42C0B8538F58A3BB1B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:GLS Gozi Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:RIMESSA_CASSEGNI03016023_3764.js
File size:6'989'246 bytes
SHA256 hash: 2a72302c1e76b436da9f0e37941a6e3c1f9921a54bc0bf78d7fe90cf876a6516
MD5 hash: d771a73b5dcc5ce0bde8b9b86b03fc35
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Behaviour
BlacklistAPI detected
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies system certificate store
Blocklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments