🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b049b7e03749e7f0819f551ef809e63f8a69e38a0a70b697f8a5a82a792a1df9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: b049b7e03749e7f0819f551ef809e63f8a69e38a0a70b697f8a5a82a792a1df9
SHA3-384 hash: b3cadc183df5a34674d5386e7d21622949655171822025b50c70598e49eb67d8b6e2891f8e9e3bf15e52ddd86943ae67
SHA1 hash: 23f005b38c089e7afbc01591d9e0780e2170a913
MD5 hash: 618eb8f17aad6b95e5989bc1e376406a
humanhash: sink-louisiana-speaker-item
File name:gDIeYy.au3
Download: download sample
Signature DarkGate
File size:774'502 bytes
First seen:2023-10-26 08:34:34 UTC
Last seen:Never
File type:
MIME type:text/plain
ssdeep 12288:0lb99SEM9gA3BVVTvXuB0RyiDhDh4JAqt9AFwsUxw5TaTOge+:0BlM9gARNy4TWMywwu+
TLSH T1ECF4B077EF81BA6FEEE2E8444645A7EA63D1B4D99B420D0F45702B4BC27CD4A1B4340E
Reporter plebourhis
Tags:au3 DarkGate


Avatar
plebourhis
Darkgate AutoIT script

Intelligence


File Origin
# of uploads :
1
# of downloads :
209
Origin country :
FR FR
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2.5/10
Confidence:
100%
Tags:
javascript masquerade
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via e-mail link

Comments