🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2bf00d0e3d2462f9d02f4e5f9583cd7c445fac183fa7b417652bb175c609bb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f2bf00d0e3d2462f9d02f4e5f9583cd7c445fac183fa7b417652bb175c609bb2
SHA3-384 hash: ba5aa7464262f8492ee0b557488cbcd179e36a63642db583f088052fe02187e563cdf76c4622a03eb3ed99667c419c1d
SHA1 hash: 5ce33e2bb3346565e222cc3d1c9110e3fe1292d7
MD5 hash: e932d727fb2a88835d822316bde5ab89
humanhash: sierra-shade-wolfram-nitrogen
File name:script
Download: download sample
Signature Gozi
File size:209 bytes
First seen:2022-12-07 04:39:38 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3:SnfYkh4ktQwgD2adAwLXHPtwrWFFdAFEeIAYRmRLIUApLsVB+xMeFk9eOD6L4A78:efxHOwUbCWmFvGw24+s9e06kHf5mXyn
TLSH T1AFD023551E05FDF5C0400BC9FF179C14D42319E40906E63083CD4C89A421408D7DDC76
Reporter JAMESWT_WT
Tags:agenziaentrate agenziaonline-top Gozi Loader ps1 script Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
264
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
powershell
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus detection for URL or domain
Snort IDS alert for network traffic
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 762406 Sample: script.ps1 Startdate: 07/12/2022 Architecture: WINDOWS Score: 56 17 Snort IDS alert for network traffic 2->17 19 Antivirus detection for URL or domain 2->19 6 powershell.exe 14 20 2->6         started        process3 dnsIp4 15 onlineagenzia.top 62.173.154.137, 49696, 49697, 80 SPACENET-ASInternetServiceProviderRU Russian Federation 6->15 9 svchost.exe 6->9         started        11 conhost.exe 6->11         started        13 rundll32.exe 6->13         started        process5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://onlineagenzia.top/registr.dll
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments