🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc3f72f5b7e213db08c072250f890bce43228cda3d5486df6d417e8dbde051ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cc3f72f5b7e213db08c072250f890bce43228cda3d5486df6d417e8dbde051ac
SHA3-384 hash: eaa4527b83f7ceb576e6f0f9010d92aacac6a056c3f0b67c9cdd5817e8ab46873db86965b742c034796959c77d275984
SHA1 hash: c0268f6790473d5d1d03dd9942047498a6d8d381
MD5 hash: c563dfb4f525af1f38604954242478ac
humanhash: utah-tennis-april-magazine
File name:E.pdf
Download: download sample
Signature DarkGate
File size:18'585 bytes
First seen:2023-10-13 11:18:07 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:4A8KHlmkspsg77Sr2pQTvyJipl0xx+65kxIMl5udiXeUXzX3qrynh:4XK4tpb7796+ipl/xIm5EmrX3qoh
TLSH T1D482AE07B2185CECE9569837CA3C751A48FDB58B95C07EB4723606CEB0DF49552032FA
Reporter 0x_malw_research
Tags:DarkGate pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
517
Origin country :
GB GB
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
1.7/10
Score Malicious:
17%
Score Benign:
83%
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for domain / URL
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1325237 Sample: E.pdf Startdate: 13/10/2023 Architecture: WINDOWS Score: 48 29 Multi AV Scanner detection for domain / URL 2->29 7 chrome.exe 9 2->7         started        10 Acrobat.exe 20 62 2->10         started        process3 dnsIp4 19 192.168.2.8, 138, 443, 49704 unknown unknown 7->19 21 239.255.255.250 unknown Reserved 7->21 12 chrome.exe 7->12         started        15 AcroCEF.exe 77 10->15         started        process5 dnsIp6 23 affaires.co.in 192.185.157.35, 443, 49728, 49729 UNIFIEDLAYER-AS-1US United States 12->23 25 clients.l.google.com 142.250.176.14, 443, 49726 GOOGLEUS United States 12->25 27 5 other IPs or domains 12->27 17 AcroCEF.exe 4 15->17         started        process7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkGate

pdf cc3f72f5b7e213db08c072250f890bce43228cda3d5486df6d417e8dbde051ac

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments