🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 28fd21516af228e2aa595e44cbbe8ab95bbd438d70d94fc715ee04221d88c0da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments 1

SHA256 hash: 28fd21516af228e2aa595e44cbbe8ab95bbd438d70d94fc715ee04221d88c0da
SHA3-384 hash: e2af0fc800ffc054a9da0a0a8d7e745ca0488ab2076e6ddaae2a90283885d85270f141e275ae745ec789c2284d6bc52b
SHA1 hash: 172d46833ca2638a14c93546fce57b6870db2e06
MD5 hash: ac73a3eff4a3884354e4b7e07821e88b
humanhash: winter-pip-arkansas-gee
File name:Lingiang_Cosmetic_Promotion_Program_2023 Approved.by.CEO.docx
Download: download sample
Signature DarkGate
File size:6'863 bytes
First seen:2023-09-29 06:54:26 UTC
Last seen:Never
File type:Word file doc
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 192:VFksslsSRDC0Gu0vaK3Z1xlCl31jq4JDdU+m:ZcGO0vaQNlw311JRU+m
TLSH T1EDE16C34ED67E469E50711F2D151D5B7EC458487C25AE36FA50C26C88BA0F932B43EDC
TrID 51.0% (.DOCX) Word Microsoft Office Open XML Format document (23500/1/4)
38.0% (.ZIP) Open Packaging Conventions container (17500/1/4)
8.6% (.ZIP) ZIP compressed archive (4000/1)
2.1% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter r3dbU7z
Tags:DarkGate doc docx stager

Intelligence


File Origin
# of uploads :
1
# of downloads :
448
Origin country :
RU RU
Vendor Threat Intelligence
Verdict:
File type:
application/msword
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Creating a window
Сreating synchronization primitives
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
masquerade
Label:
Benign
Suspicious Score:
3/10
Score Malicious:
3%
Score Benign:
97%
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2023-09-29 06:55:06 UTC
File Type:
Document
Extracted files:
11
AV detection:
3 of 22 (13.64%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DarkGate

Word file doc 28fd21516af228e2aa595e44cbbe8ab95bbd438d70d94fc715ee04221d88c0da

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2023-10-03 15:06:12 UTC

Can you provide more details on the doc? I'm not able to detonate it.