🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0f62fb2258e35b1588c8b5c916e79b0102c5ee373a8f65ceb4864d201fceb21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: f0f62fb2258e35b1588c8b5c916e79b0102c5ee373a8f65ceb4864d201fceb21
SHA3-384 hash: 585ecc456a35a289603800f0f2a95d7fc6f56eec0592da00531ac74afd1f27f78013c88596057d7fe5311d94d2be49c2
SHA1 hash: 0aa8bce8b55cf59581dfcfb85314483f0cea9154
MD5 hash: 76e6f6d4174a752388f0bfe407e57add
humanhash: purple-double-virginia-carpet
File name:printouts of outstanding as of 20230606.zip
Download: download sample
Signature Gozi
File size:44'080 bytes
First seen:2023-06-06 18:41:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:BTC3WR77Bc9/TagzBBHH8rNvlf3SUe32bUGi56zN2/y1ZKdP:7PBAr8rNdfSr2I0zN6y6dP
TLSH T158130195AF6B9960CED719C11ABFB43F07A462C4CE83AB5AE48818423EF4593F75C443
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter fr0s7_
Tags:Gozi mikehp-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
189
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:printouts of outstanding as of 06062023.js
File size:105'585 bytes
SHA256 hash: d025ee7d2be36308e13ea988e3e15ab0e687972624ff88db059d472df7f46253
MD5 hash: e8b5043f0f263f7f66bdee786904268b
MIME type:text/plain
Signature Gozi
Vendor Threat Intelligence
Result
Verdict:
Clean
File Type:
JS File
Payload URLs
URL
File name
https://dxr.mozilla.org/mozilla-central/source/toolkit/crashreporter
JS File
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Threat name:
Binary.Malware.Generic
Status:
Suspicious
First seen:
2023-06-06 18:42:05 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
3 of 37 (8.11%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments