🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6311ed9b17dfee292dcdc9dabbde47a1148e384c33d8ee8294b3e32111ce80a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 6311ed9b17dfee292dcdc9dabbde47a1148e384c33d8ee8294b3e32111ce80a4
SHA3-384 hash: f8c75c813930a48d403cfc04f706f332c421259e88fae75fbd9fb09cb6fd8508b0e30864a949323ef1c3790a10d0fc8c
SHA1 hash: e322945144ae4d3969676fdfc061f40f7db34792
MD5 hash: e5b79cfca6f19fd7c119f9ab717f165b
humanhash: asparagus-kentucky-jersey-california
File name:darkgate_shellcode.bin
Download: download sample
Signature DarkGate
File size:108'045 bytes
First seen:2023-09-13 08:56:23 UTC
Last seen:Never
File type:unknown
MIME type:application/octet-stream
ssdeep 3072:1ISsaU0qWDNVjhSo1rYuqUY9BbR6WsP64LlDrfmXTY:uaFVjEckuqB9x8PvLhrejY
TLSH T1C0B3292BDDE04F811D0740A19AFD27C92BFB8812BDFCDADB63B74C8595ABA3520451E1
Reporter 0xToxin
Tags:DarkGate zochao-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
143
Origin country :
IL IL
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:meth_stackstrings
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments