🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09bf1b88716c49a62cb4ff708f7ff4f09cb7c3ff42e58661802cd66f1a2a0311. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 09bf1b88716c49a62cb4ff708f7ff4f09cb7c3ff42e58661802cd66f1a2a0311
SHA3-384 hash: 519a9e29a9c8f297069e793b7ee569ba7b66bf296d3375bad29b80dff0e09eaff7e91b4ff72e57e7db3100af982ac9c9
SHA1 hash: 5a1585479349ab9a64134ce4a3063b513aabb9ce
MD5 hash: 851bdfe9ea52b59d50b8d2de086921c9
humanhash: sweet-twenty-grey-earth
File name:dgYoooUm.au3
Download: download sample
Signature DarkGate
File size:769'468 bytes
First seen:2023-07-25 13:05:18 UTC
Last seen:Never
File type:
MIME type:text/plain
ssdeep 12288:S7k7ag2ZA0BSemCiZUYeaFCjWuweGqJ/4QDHrii6OoM:SeD2SHeWuwItWiloM
TLSH T149F4AD4A1F6D4D2A4F8EA05D22787A7F1FA078D1D2E4F47D68479F55A09EF200CB8E09
Reporter JAMESWT_WT
Tags:80-66-88-145 au3 config DarkGate

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
javascript masquerade
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments