🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2629b7c8c2e9b2357904b4a29c8d211bee5c45f0fa532941c41385e7fb58bfcf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2629b7c8c2e9b2357904b4a29c8d211bee5c45f0fa532941c41385e7fb58bfcf
SHA3-384 hash: 1b4ac0d7c3a316989789d8536dd27f544d10e64ca68cbe6b6930162b36cf496aafb0457191574e868326d2c340776cda
SHA1 hash: 1f7a25ac29df628728d1c1043ba4046e3874a3c4
MD5 hash: 22bcbd0998140e08616283d35385beda
humanhash: tennis-equal-single-iowa
File name:n.pdf
Download: download sample
Signature DarkGate
File size:42'713 bytes
First seen:2023-10-10 10:47:04 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 768:eDJvSAQmWmLVOEa0B0neWFaiITWY1G6eNZW1/ScIkADBDx0DUR6mexZDVfVf:eDQr8OTBeWFaiITWaGqqgADBD5eFNf
TLSH T1C61302CA705889CCC3800989B57D339E4D7D781A36F33E8D5AD64902B918661F8A7773
Reporter JAMESWT_WT
Tags:DarkGate pdf stolenconversation

Intelligence


File Origin
# of uploads :
1
# of downloads :
551
Origin country :
IT IT
Vendor Threat Intelligence
Gathering data
Label:
Benign
Suspicious Score:
1.6/10
Score Malicious:
17%
Score Benign:
83%
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Downloads suspicious files via Chrome
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1322774 Sample: n.pdf Startdate: 10/10/2023 Architecture: WINDOWS Score: 23 34 Downloads suspicious files via Chrome 2->34 7 chrome.exe 23 2->7         started        11 Acrobat.exe 20 62 2->11         started        process3 dnsIp4 22 192.168.2.22 unknown unknown 7->22 24 192.168.2.3, 138, 443, 49474 unknown unknown 7->24 26 4 other IPs or domains 7->26 20 C:\Users\user\Downloads\Data.zip (copy), Zip 7->20 dropped 13 chrome.exe 7->13         started        16 AcroCEF.exe 84 11->16         started        file5 process6 dnsIp7 28 accounts.google.com 142.250.217.141, 443, 49728 GOOGLEUS United States 13->28 30 142.250.72.142, 443, 49749 GOOGLEUS United States 13->30 32 6 other IPs or domains 13->32 18 AcroCEF.exe 4 16->18         started        process8
Threat name:
Document-PDF.Trojan.DarkGate
Status:
Malicious
First seen:
2023-10-10 10:48:03 UTC
File Type:
Document
Extracted files:
3
AV detection:
11 of 20 (55.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments