MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 84ecd659287e5d1bb28f94f8839e7b8e74aff06c528ef04675047cd06e7b7d9f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
DarkGate
Vendor detections: 7
| SHA256 hash: | 84ecd659287e5d1bb28f94f8839e7b8e74aff06c528ef04675047cd06e7b7d9f |
|---|---|
| SHA3-384 hash: | 654b55ea09980f21c4953225ba086e095a9896845ee4da2b4d9dfc3b1d3b2c5accdc13e45f9c5c9357a53a98b9aa8043 |
| SHA1 hash: | d04b18ce9809a3bf61920c2cd44b5e4720d9d617 |
| MD5 hash: | 0ff9527dfb3bb2323608fc010f6da2e4 |
| humanhash: | winter-river-crazy-colorado |
| File name: | claim-11-2-882IEO776-23.pdf |
| Download: | download sample |
| Signature | DarkGate |
| File size: | 212'459 bytes |
| First seen: | 2023-11-07 04:41:03 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/pdf |
| ssdeep | 6144:iai3/or3B8vmAii7rmHww2ArEJmR7uPdRSAJF/f0:iai3Ar3KnrmQw2A4OAdRPF/M |
| TLSH | T1BF2401A83435C450DD9BA5B11B5C3FC3A5CBC1F218D62023D072AA9F367EC23B4A15EA |
| Reporter | |
| Tags: | DarkGate pdf |
V3n0mStrike
#darkgate campaign .cab file download from https://adclick.g.doubleclick.net/pcs/click?fj2-NOVEMBER-23-RefHHB119kd&&adurl=//marmorariaxangrila.com.br/Intelligence
File Origin
# of uploads :
1
# of downloads :
753
Origin country :
CLVendor Threat Intelligence
Detection(s):
Result
Verdict:
Clean
File Type:
PDF File
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Trojan.Generic
Label:
Benign
Suspicious Score:
4.0/10
Score Malicious:
41%
Score Benign:
59%
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Suspicious PDF detected (based on various text indicators)
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2023-11-03 16:57:55 UTC
File Type:
Document
Extracted files:
58
AV detection:
11 of 38 (28.95%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.40
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.