MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ed72da56c92e39da96db9f91852481837c2e96f09cfb198c3b5671054ac0e45c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ed72da56c92e39da96db9f91852481837c2e96f09cfb198c3b5671054ac0e45c
SHA3-384 hash: 1c0ce28b1ef6f63beeb33a1f51ec65e1ac6d7a37fbb16d40ed7a869f3f048ece0a8d361d0bbcddb1a730d117cb7ff84b
SHA1 hash: 3322cd8e2bf7d03a7a2833dcd0f116ae9407b075
MD5 hash: e4b75b0e578577c7e020a298a1a1e449
humanhash: blossom-timing-single-comet
File name:servizi
Download: download sample
Signature Gozi
File size:2'202'949 bytes
First seen:2023-05-19 01:46:02 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:gcYPcYM6uT8itShWkSHr0ArZOGttbPWxnqWGlueDkZdc/xegxJh:m5iuWBJqpqPl/kDc/xNh
TLSH T17BA5124F45734EECABD81E9C1CB91FD91A98BD7135A4FDD19C3B20434A326B920B6827
Reporter JAMESWT_WT
Tags:Gozi js vipbeed-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2023-05-19 01:32:58 UTC
File Type:
Text
AV detection:
3 of 37 (8.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments