MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d8bbe9c45a9380f0312740bd154bbdb88aca4183ab6aa7e15eb2b652f33c8e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkMe


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 6d8bbe9c45a9380f0312740bd154bbdb88aca4183ab6aa7e15eb2b652f33c8e6
SHA3-384 hash: e23c9b9d1f71d5052f9164487f67704d8bad4ced9114c7aac4b39fb98a83aaa8ba2611d21810fbcca821c4543da8359b
SHA1 hash: 0f797f3d5ce9bb0a6fd0b8208ab17a97ba165de1
MD5 hash: dadcbd96fbc67634350408903490193d
humanhash: carbon-minnesota-saturn-mango
File name:Damned.dll
Download: download sample
Signature DarkMe
File size:28'672 bytes
First seen:2026-06-27 12:58:22 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 157bb20098004a7677015ef0dea0fd7a (1 x DarkMe)
ssdeep 192:5JBA+sfQwz0pD7NsHnQeh5dFV97Bh3LehID9T/A6QZsFDBKW3:5jA+HZD7NmdbNZ9T/QqDL3
TLSH T131D2C515B2CBD17BE29846B11E22D7EC2105BE106FC2CA5F71ECB75EBF7A1008560B1A
TrID 21.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
21.2% (.EXE) Win64 Executable (generic) (6522/11/2)
16.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
14.6% (.EXE) Win32 Executable (generic) (4504/4/1)
6.6% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter marsomx
Tags:DarkMe dll ITA

Intelligence


File Origin
# of uploads :
1
# of downloads :
143
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
visual_basic
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Visual Basic Visual Basic 6 Win 32 Exe x86
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware discovery persistence ransomware spyware
Behaviour
Checks SCSI registry key(s)
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
System Location Discovery: System Language Discovery
Enumerates connected drives
Boot or Logon Autostart Execution: Active Setup
Unpacked files
SH256 hash:
6d8bbe9c45a9380f0312740bd154bbdb88aca4183ab6aa7e15eb2b652f33c8e6
MD5 hash:
dadcbd96fbc67634350408903490193d
SHA1 hash:
0f797f3d5ce9bb0a6fd0b8208ab17a97ba165de1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments