🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69377a13644e0e1dd5abbfaadcac2712b63cc3e797fb7b355eddfb3184dac619. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 69377a13644e0e1dd5abbfaadcac2712b63cc3e797fb7b355eddfb3184dac619
SHA3-384 hash: 1e630b5e6a7d99768dea45171b5c58a9a8d83754377991db284adb1aec6c839673a7879b94a1a89a07b072056f984077
SHA1 hash: daf3b007842c673c02e1563a41df9cc695353722
MD5 hash: 65781ba4fd05e1700b137ab91119e89c
humanhash: autumn-cup-mirror-six
File name:dm.zip
Download: download sample
Signature DarkGate
File size:822'907 bytes
First seen:2024-02-02 21:00:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:3hjJs9uHpnB7DNbnDJ4wFY8YXsCdLsXOjJu/Y1pRMHSgIczkYdPgcQOkSkBqUr9e:xls9eB1jCwFY8cseNu/QpKH6K/UopB
TLSH T1AE0533240A881DCC2E744615A640FBBFFD54E044AA5CB3A6D6E6947EFC1D1F4CA2F8D8
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter rmceoin
Tags:DarkGate zip


Avatar
rmceoin
file://45.153.242.76@80/Downloads/TaxForm.lnk

Intelligence


File Origin
# of uploads :
1
# of downloads :
305
Origin country :
US US
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:script.au3
File size:589'538 bytes
SHA256 hash: 2f5fe4ed3df8d38dec93cd7d90e17d96993f42948cb7b6095bd4a91d3cd335d2
MD5 hash: 89c898c56f5a4d9f995d6f34e2930a9f
MIME type:application/octet-stream
Signature DarkGate
File name:Autoit3.exe
File size:893'608 bytes
SHA256 hash: 237d1bca6e056df5bb16a1216a434634109478f882d3b1d58344c801d184f95d
MD5 hash: c56b5f0201a3b3de53e561fe76912bfd
MIME type:application/x-dosexec
Signature DarkGate
File name:test.txt
File size:76 bytes
SHA256 hash: f71f2d66cefc79aa0392fa509eca3910e66a812172b8837f54c92c94d0e6764c
MD5 hash: 5709d2e7ca1a70a9522632aa62508655
MIME type:text/plain
Signature DarkGate
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
autoit fingerprint keylogger lolbin overlay packed shell32
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Script
Author:@bartblaze
Description:Identifies AutoIT script. This rule by itself does NOT necessarily mean the detected file is malicious.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DarkGate

zip 69377a13644e0e1dd5abbfaadcac2712b63cc3e797fb7b355eddfb3184dac619

(this sample)

Comments