🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ed93537b8b5b70b143394fe0be400a7419d0204e9b9d6f1081f22c1f4c0a221f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ed93537b8b5b70b143394fe0be400a7419d0204e9b9d6f1081f22c1f4c0a221f
SHA3-384 hash: 47e39ba439224d33e276bc4bc349770f592d32294dbdb28f83bfa9c3e0b306695af17ab3bc42faa227ea7083272328b6
SHA1 hash: a5fbd87667c8a3214052b51700ba566be9b3e925
MD5 hash: 5400b53bfcd00f3db1f67ce0125a8169
humanhash: five-golf-thirteen-eight
File name:Fattura 3560 2023-400927.js
Download: download sample
Signature Gozi
File size:20'462 bytes
First seen:2023-04-28 06:34:25 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:WNNnHXEHCJJ0UYniiT2B2pwpalhkCFIpKe/LIP1kUm9X4tW/Jx9zDTX3qGRNW97y:UKCP0UYntT2B2qpaliCFEKe/LIP1kUmP
TLSH T14492D2E080269B568F6170EA7934C658FB110D6B4B4C7D8BBE2D3120FBFA54CDDA6036
Reporter JAMESWT_WT
Tags:DhlCredit Gozi js js1 Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
316
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
sload
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
JScript performs obfuscated calls to suspicious functions
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Threat name:
Script-JS.Trojan.Ursnif
Status:
Suspicious
First seen:
2023-04-27 09:06:33 UTC
File Type:
Text (JavaScript)
AV detection:
3 of 37 (8.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments