🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 898d17126aeca469960cb6d4fbe07335a9cff6a800a6eeff087a93ff5cb35fbe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 898d17126aeca469960cb6d4fbe07335a9cff6a800a6eeff087a93ff5cb35fbe
SHA3-384 hash: f4a72ba11b127c8a5d91346a26c91804b9f2427395c566a23dacd81dbc1c77d247aa3e1e742057e09ba0a68ec0660451
SHA1 hash: 96e19eaf542cbd0f0f3ac3af97d3aff5e455efd2
MD5 hash: cf04717ce48e75793d8548d7fbeaba30
humanhash: florida-orange-mobile-bacon
File name:7c.vbs
Download: download sample
Signature DarkGate
File size:2'326 bytes
First seen:2023-09-28 11:04:13 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:JU0enL/CWSiFicH9gfJcuOa3LZJiiYg6m9CFq3no:JUzLKUi26fJMaSiRgFUo
TLSH T13A419833EA0EC9E7C41A737145870B94DD56047C3366DA4DBA38E01E3725A6E09D4AA2
Reporter marqufabi
Tags:AA11 DarkGate ta577 vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
192
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
33%
Tags:
anti-vm
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
76 / 100
Signature
Antivirus detection for URL or domain
Leaks process information
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Behaviour
Behavior Graph:
Threat name:
Script-WScript.Trojan.Darkgate
Status:
Malicious
First seen:
2023-09-28 11:05:04 UTC
File Type:
Binary
AV detection:
5 of 23 (21.74%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Script User-Agent
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments