🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84ecd659287e5d1bb28f94f8839e7b8e74aff06c528ef04675047cd06e7b7d9f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 84ecd659287e5d1bb28f94f8839e7b8e74aff06c528ef04675047cd06e7b7d9f
SHA3-384 hash: 654b55ea09980f21c4953225ba086e095a9896845ee4da2b4d9dfc3b1d3b2c5accdc13e45f9c5c9357a53a98b9aa8043
SHA1 hash: d04b18ce9809a3bf61920c2cd44b5e4720d9d617
MD5 hash: 0ff9527dfb3bb2323608fc010f6da2e4
humanhash: winter-river-crazy-colorado
File name:claim-11-2-882IEO776-23.pdf
Download: download sample
Signature DarkGate
File size:212'459 bytes
First seen:2023-11-07 04:41:03 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:iai3/or3B8vmAii7rmHww2ArEJmR7uPdRSAJF/f0:iai3Ar3KnrmQw2A4OAdRPF/M
TLSH T1BF2401A83435C450DD9BA5B11B5C3FC3A5CBC1F218D62023D072AA9F367EC23B4A15EA
Reporter V3n0mStrike
Tags:DarkGate pdf


Avatar
V3n0mStrike
#darkgate campaign .cab file download from https://adclick.g.doubleclick.net/pcs/click?fj2-NOVEMBER-23-RefHHB119kd&&adurl=//marmorariaxangrila.com.br/

Intelligence


File Origin
# of uploads :
1
# of downloads :
753
Origin country :
CL CL
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
4.0/10
Score Malicious:
41%
Score Benign:
59%
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Suspicious PDF detected (based on various text indicators)
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2023-11-03 16:57:55 UTC
File Type:
Document
Extracted files:
58
AV detection:
11 of 38 (28.95%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkGate

pdf 84ecd659287e5d1bb28f94f8839e7b8e74aff06c528ef04675047cd06e7b7d9f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments