🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 de05527564eedea50f0dace07d2bebc7aa32593d23ea7eba02bae002789816d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: de05527564eedea50f0dace07d2bebc7aa32593d23ea7eba02bae002789816d6
SHA3-384 hash: a0d74e9153fb603338029f4d262bb647b38128f52a4378da95271ed05b3b33cea24ca5e1d648db1e873b5c0df80b102c
SHA1 hash: 655321deb1c2eac06be9bab4969ee30a9ee44bba
MD5 hash: 3edf1f7fd566e51ec66b9eef25afc652
humanhash: august-don-washington-lion
File name:Agenzia_07.zip
Download: download sample
Signature Gozi
File size:389 bytes
First seen:2022-02-10 10:21:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12:5jvhL4Pj2F8EIxuoN1r0b7N6g97EtLwaMP:9x4Pj9xuoP0x627gU
TLSH T197E0684343821302F06AC3BDDA15AA5E932CC3AA00A462EA1483B0DD4C411DDAD8A608
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
460
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2022-02-10 10:22:06 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
3 of 43 (6.98%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments