🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 529d3eccf1000887f5e35b3eb8e732066b819201f37651d1ccca41d5cc2c1513. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 529d3eccf1000887f5e35b3eb8e732066b819201f37651d1ccca41d5cc2c1513
SHA3-384 hash: 10d68d638e0d5dc7e94f9cb506f45674cbd078c1f8bfc5a035ba4275f3de5deee6e563f0ff1331678ec4d1c8fdd86dba
SHA1 hash: f2a20c2d69c7dcd93edcd83f2ba4cf84126fe7fd
MD5 hash: 63bd0b13bf96807afef4f53bddc7d59a
humanhash: fifteen-blue-london-lactose
File name:11.url
Download: download sample
Signature DarkGate
File size:158 bytes
First seen:2023-12-13 14:51:16 UTC
Last seen:Never
File type:
MIME type:application/octet-stream
ssdeep 3:HRAbABGQYmaUMv+kJZgKQI89qe1YSo/QJ4ovstyYesbBSl:HRYFVmapvJZPQI89ISoIJlvstyYesbBW
TLSH T143C08C08829FD425C077884DCE088CEEF88398872516C83243A12D88EC87CA93EC88DD
TrID 91.6% (.URL) Windows URL shortcut (11000/1/2)
8.3% (.INI) Generic INI configuration (1000/1)
Reporter abuse_ch
Tags:DarkGate url


Avatar
abuse_ch
DarkGate malspam campaign:
https://adclick.g.doubleclick.net/pcs/click?adurl=//balkarsoftware.cubistech.com
-> https://balkarsoftware.cubistech.com/
--> https://balkarsoftware.cubistech.com/public/build/important/DEC-872667-2023.zip
---> http://5.181.156.243/Downloads/11.url
----> http://5.181.156.243/Downloads/filactery.zip
-----> http://cdn3-adb1.online/abdwufkw/modules/cleanhelper.png
-----> http://cdn3-adb1.online/abdwufkw/modules/legacy_l1.png
-----> http://cdn3-adb1.online/abdwufkw/modules/runsysclean.png

Intelligence


File Origin
# of uploads :
1
# of downloads :
180
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
rat
Threat name:
Script-JS.Trojan.UrlDownloader
Status:
Malicious
First seen:
2023-12-13 14:52:03 UTC
File Type:
Text
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

3d8bc2118cc6f57a2ea3698f7360e488

DarkGate

529d3eccf1000887f5e35b3eb8e732066b819201f37651d1ccca41d5cc2c1513

(this sample)

  
Dropped by
MD5 3d8bc2118cc6f57a2ea3698f7360e488
  
Delivery method
Distributed via web download

Comments