🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e2c428dd59fca3ab6ed117697aab34cc92a186c0c28ce41fccf2f765697090a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9e2c428dd59fca3ab6ed117697aab34cc92a186c0c28ce41fccf2f765697090a
SHA3-384 hash: 2100f995537d9bb29f65933186bde37bdb33640b65e9d31dda63660b40b0e80dd2b48ebbae0608edbf08530288d9baa3
SHA1 hash: 18e80df462db252f81b32a22a845f8acc253df5b
MD5 hash: 3835ea8ca799e304684d111208b9ab62
humanhash: sink-zebra-eighteen-oscar
File name:claim-nov-2-187IAA623.pdf
Download: download sample
Signature DarkGate
File size:115'183 bytes
First seen:2023-11-07 04:30:10 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:6tHUZHIxpx4410iDEuQ6xaCmdNnExCoPh2n3R7IP8ZkjLihY4LYo1qhar/:Q+s4AJoSsnEHs35I/jLiy4YMqhar/
TLSH T134B3BFFAE53AC0C8D4428650A99C27D794DEC0F7595924B7387CCA833A4DE95FC205FA
Reporter V3n0mStrike
Tags:DarkGate pdf


Avatar
V3n0mStrike
#darkgate .cab file download from https://adclick.g.doubleclick.net/pcs/click?fj2-NOVEMBER-23-RefHHB119kd&&adurl=//nuriaperaire.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
601
Origin country :
CL CL
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
phishing
Label:
Benign
Suspicious Score:
4.0/10
Score Malicious:
41%
Score Benign:
59%
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Suspicious PDF detected (based on various text indicators)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1338044 Sample: claim-nov-2-187IAA623.pdf Startdate: 07/11/2023 Architecture: WINDOWS Score: 76 25 youtube-ui.l.google.com 2->25 27 www.youtube.com 2->27 41 Multi AV Scanner detection for domain / URL 2->41 43 Antivirus detection for URL or domain 2->43 45 Antivirus / Scanner detection for submitted sample 2->45 47 2 other signatures 2->47 8 chrome.exe 1 2->8         started        11 Acrobat.exe 20 76 2->11         started        signatures3 process4 dnsIp5 31 192.168.2.4 unknown unknown 8->31 33 239.255.255.250 unknown Reserved 8->33 13 chrome.exe 8->13         started        16 chrome.exe 8->16         started        18 chrome.exe 6 8->18         started        20 AcroCEF.exe 72 11->20         started        process6 dnsIp7 35 104.244.42.136 TWITTERUS United States 13->35 37 104.244.42.72 TWITTERUS United States 13->37 39 48 other IPs or domains 13->39 22 AcroCEF.exe 2 20->22         started        process8 dnsIp9 29 23.62.208.138 GTT-BACKBONEGTTDE United States 22->29
Threat name:
Document-PDF.Phishing.Generic
Status:
Malicious
First seen:
2023-11-02 17:54:16 UTC
File Type:
Document
Extracted files:
134
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkGate

pdf 9e2c428dd59fca3ab6ed117697aab34cc92a186c0c28ce41fccf2f765697090a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments