🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2766eeb9422ef9dccc1f208e7cbb807c57decae2b08d82995aaf897a67583c94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2766eeb9422ef9dccc1f208e7cbb807c57decae2b08d82995aaf897a67583c94
SHA3-384 hash: 04d4debe2d8952461ff37e77d0f50a20ca211758b9384b07fdf14a65d19af114ce4418a6c3cf8ebb81d8fec932244481
SHA1 hash: 2757c793b96639f3bca33bdd07576d3ad95d063b
MD5 hash: 60d07f9e7daf81bb5a9bb4b3bed41bfd
humanhash: hotel-fish-may-monkey
File name:march19-D3145-2024[1314225].xlsx
Download: download sample
Signature DarkGate
File size:57'772 bytes
First seen:2024-03-19 16:48:55 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 1536:Fkws9oLE3Ow6DyPgMUti9xx7bxNfI5ydaRLgIui3pqDyBROnlTE:FSoEOfEgMNdxI5yYhgu5zBRYg
TLSH T17443F16F944F085EC6F000BD442F41A74987348B35722E2B6891799CDE86BE7B7E36C9
TrID 60.1% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
30.9% (.ZIP) Open Packaging Conventions container (17500/1/4)
7.0% (.ZIP) ZIP compressed archive (4000/1)
1.7% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter k3dg3___
Tags:admin888 DarkGate xlsx

Intelligence


File Origin
# of uploads :
1
# of downloads :
2'805
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2766eeb9422ef9dccc1f208e7cbb807c57decae2b08d82995aaf897a67583c94.xlsx
Verdict:
No threats detected
Analysis date:
2024-03-19 16:49:01 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/octet-stream
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Using the Windows Management Instrumentation requests
Creating a window
Сreating synchronization primitives
Launching a process
Moving a file to the Program Files subdirectory
Replacing files
Result
Verdict:
Suspicious
File Type:
OOXML Excel File
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
explorer lolbin
Label:
Benign
Suspicious Score:
3.4/10
Score Malicious:
35%
Score Benign:
65%
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.expl.evad
Score:
60 / 100
Signature
Detected suspicious Microsoft Office reference URL
Document Viewer accesses SMB path (likely to steal NTLM hashes or to download payload)
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Opens network shares
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkGate

Excel file xlsx 2766eeb9422ef9dccc1f208e7cbb807c57decae2b08d82995aaf897a67583c94

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments