🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf2a69d4728af507440925f462a41bac0529dd70eec76ff8b5988bf510bea8ef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bf2a69d4728af507440925f462a41bac0529dd70eec76ff8b5988bf510bea8ef
SHA3-384 hash: 45e6e059747c7cfc5fe10244205b8db621d0ffa61860573dc1f694eb08f46c37f973ba57373d9d173eb897d45eea5634
SHA1 hash: 15d0fb9e6e55149920018e7b5a4cff81fb0ed81c
MD5 hash: 48d19dd48fc803b47b7a804b47332a6a
humanhash: carpet-victor-enemy-robert
File name:kcx.zip
Download: download sample
Signature DarkGate
File size:4'422 bytes
First seen:2023-10-13 11:15:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 96:cjppacwfcHaFYg6E7VW0DW4iD7qvIWq4TLQymsyJm:cacjAYg6T0DPXL4q
TLSH T150917EB9140C3A21CA8F89BBD543D90DD1E610F5E2AD6861D7C246C215F2E42AE365B6
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:DarkGate zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
180
Origin country :
US US
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Doc-94.vbs
File size:26'520 bytes
SHA256 hash: 1e8a6d34c0fe5a5ad2fc1d6ff7000bcf8efa0704c397cb6ef021c2692bf17fe6
MD5 hash: d050315ff65ebef0ba1352167126592f
MIME type:text/plain
Signature DarkGate
File name:Doc-94.txt
File size:30 bytes
SHA256 hash: 1a830094eaa0842150317fad2c111526eba09faf4be1e85c1561998725b796cf
MD5 hash: 145dfc2b25897367e250aabab8680600
MIME type:text/plain
Signature DarkGate
Vendor Threat Intelligence
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments