🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd1f757b4a90e009c67110dc9e24660c830e61aa1f16a3679cd36055c8ba3a41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: dd1f757b4a90e009c67110dc9e24660c830e61aa1f16a3679cd36055c8ba3a41
SHA3-384 hash: 62022315ef8c22859a426adbceda5f7906cd0ba13948705adc49607d0fbe9476c6aa28807212b5bc44de1e78a08f26f0
SHA1 hash: 8bcffa1488ae876beac74581668d42555e125655
MD5 hash: 1f38042a4264617e03489fe53ab7b6a1
humanhash: zulu-papa-minnesota-kitten
File name:documentaz_819.zip
Download: download sample
Signature Gozi
File size:1'983 bytes
First seen:2022-02-22 09:38:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9LoEF++vn7lANcbtPcpRv3Vf+HVixz1REjXYDfTiC:Wi7YwtEpRtf+ORRDD7iC
TLSH T1A041D6A6D76A8007D0613AB738A9F560242A562E9D09708227EBE48079B11FC6ED6C95
Reporter JAMESWT_WT
Tags:Gozi inps Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
388
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive mshta powershell
Threat name:
Script-WScript.Trojan.Ursnif
Status:
Malicious
First seen:
2022-02-22 09:39:08 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://baseline.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments