🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fc402ad7b53ff4a9ca527ec8f188c28fb9f42dfe171b77439c46b1912cdf18a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 3


Intelligence 3 IOCs YARA 21 File information Comments

SHA256 hash: 2fc402ad7b53ff4a9ca527ec8f188c28fb9f42dfe171b77439c46b1912cdf18a
SHA3-384 hash: a0e1bbb75767e8284d4f2c928246f9cb4ac4c778589edfdefb14595b89c3638fe086acb7afd768481431805fc9984492
SHA1 hash: e74e53bbc6734e15364ba7cb4740bbb913370755
MD5 hash: 698c708cd3749b75780d1d97f599cc09
humanhash: tango-september-oxygen-comet
File name:LH.zip
Download: download sample
Signature DarkGate
File size:2'727 bytes
First seen:2023-10-02 16:03:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 678
ssdeep 48:9Mi/Rj5d9v3zeYBAwuZaZdP4uBjqkXhAyqVwfKVw8FL8R:X/RjPp3SYewuMJjqkXhmwkw8d8R
TLSH T132514A09A4CB5EF4C3E24BBC80921613107915EA0C34AAE633E5E1C8360359A4D955AB
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:136-244-92-148 81-19-135-17 95-179-164-94 DarkGate lnk pw-678 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
AL AL
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:BQMM.pdf.lnk
File size:2'074 bytes
SHA256 hash: c523d51dc2bbb008d3d31f8aa1b9b366c7f3ec7fa0b25456d3ee036dd8ada8c9
MD5 hash: 1bc6fdedb4b6d9bd760a7e0624175068
MIME type:application/octet-stream
Signature DarkGate
File name:XC.pdf.lnk
File size:2'056 bytes
SHA256 hash: 199c04762e7697644f49d7204564def1038cacc8894b23912b0db8e86a30cf0a
MD5 hash: 35fd17ae7d69d054a19c8037d9d06bec
MIME type:application/octet-stream
Signature DarkGate
File name:2AO.pdf.lnk
File size:2'052 bytes
SHA256 hash: 34c7aec70b108d23a18b3a963bd14163d09f8242c7aef03fb99c320d0f094032
MD5 hash: be8c41dcac19e51aa5a3673478e7e676
MIME type:application/octet-stream
Signature DarkGate
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:PDF_in_LNK
Author:@bartblaze
Description:Identifies Adobe Acrobat artefacts in shortcut (LNK) files.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments