🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f987efa23c3f243e78962cab3da0de22e54732046be9efcb6672d9f61420e01e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f987efa23c3f243e78962cab3da0de22e54732046be9efcb6672d9f61420e01e
SHA3-384 hash: 478ec4f880075ddd30f8903d7a37c9b5cf02ef3bdfdfa385ae349a802d4f8974aacf5a7e2df6209eef9cce73d0306c67
SHA1 hash: e05796536d62a2cef8221ffcdc7d4a606e8b36fa
MD5 hash: a158c0c3239342b25f3f88207ed83399
humanhash: colorado-arizona-delta-washington
File name:documento7.js
Download: download sample
Signature Gozi
File size:35'095 bytes
First seen:2023-03-23 13:12:07 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:XB9K7KPK8KbKfKfKfKgSIDtbcwJYhAAKPMPA8jgos9TRlwyceKWsVA/B6n:XBkeih+SSSghDdvY0ro8VlwQKWsVA/s
TLSH T14DF2AFA829292F9DC7EFF68B62F52D66064D213F2D00DC5502479713C92B6C7F0B692E
Reporter JAMESWT_WT
Tags:EUROSPURGHI Gozi js js2 Ursnif

Intelligence


File Origin
# of uploads :
1
# of downloads :
269
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
67%
Tags:
nemucod powercat virus
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
72 / 100
Signature
Creates processes via WMI
JScript performs obfuscated calls to suspicious functions
Multi AV Scanner detection for domain / URL
Sample has a suspicious name (potential lure to open the executable)
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies system certificate store
Blocklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments