🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b5efb3fab4a283a8b00a94343b5eba7f0358d1c57f59ddb9dfdb9284459569a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 2


Intelligence 2 IOCs YARA 1 File information Comments

SHA256 hash: 6b5efb3fab4a283a8b00a94343b5eba7f0358d1c57f59ddb9dfdb9284459569a
SHA3-384 hash: 67118c7ef39510cc9b6672d56e38501749a4e23ac02987ceca9c4348277d311a862442ff20a4ea854ac4cf64cb06d9ab
SHA1 hash: 58b019b1debac0ee7e44401654c13626810e2eb3
MD5 hash: 6e6d2dd24c3c63d02eb7a1cdacf250ec
humanhash: alanine-tennessee-pizza-cardinal
File name:o.zip
Download: download sample
Signature DarkGate
File size:58'857 bytes
First seen:2023-10-10 13:37:05 UTC
Last seen:2023-10-10 13:49:55 UTC
File type: zip
MIME type:application/zip
ssdeep 1536:yEiluJv2wFrC1WsF9gQ1G+l6uXR+Ri25T1P4IaXPkfo:yvu52Um1DF8i9Af5T1P4Ia8fo
TLSH T1E043023FE46C8947D1ED21EBD8994A420E0A78B95727775B052090D6C9620FF3B0DC9B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:DarkGate zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
166
Origin country :
GE GE
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Report-8.vbs
File size:219'427 bytes
SHA256 hash: a448c4abbb2f1844a8fa0c929cd84c2f6f57a4af0442a6a4b5307af89c35cef6
MD5 hash: 726bda475bacd81fb0887a313635f3aa
MIME type:text/plain
Signature DarkGate
File name:Report-8.txt
File size:3 bytes
SHA256 hash: 721150f63b40eb6db7f277a31a3d70a73c6e8cb5cfc6133c2a0bcd8ad6451ec5
MD5 hash: 9fd6776e8c98b040d84ae25765695eee
MIME type:text/plain
Signature DarkGate
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Checks processor information in registry
Modifies system certificate store
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Blocklisted process makes network request
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments