🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce0765fa670982dce7667ca3db07b5daaa092ff4a145ed7956bc384ad2492a06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ce0765fa670982dce7667ca3db07b5daaa092ff4a145ed7956bc384ad2492a06
SHA3-384 hash: e5129f7f3aa3f4da60abaa93c1e7024fa8add691bd587fc131e769ac4a3be566cc90a9be8f6ee9073d6374533bdcdb25
SHA1 hash: 2ac83d11a878974f85d846b88181acb487ed1b2f
MD5 hash: 0dd5150067e4eb01f6397d7c97570528
humanhash: iowa-victor-arizona-dakota
File name:kni.zip
Download: download sample
Signature DarkGate
File size:85'272 bytes
First seen:2023-10-17 14:45:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:LPS+f6X6aJU/m/WV9a9s69RzOx4I4SOsP9xjMAsUWncwnvfcy9FV6pjJl3E1CPZ:LNencm/Wa9s69RziH4Gi1vf3FVKJlvZ
TLSH T149831273372AAD64E1423019721C581FDD415F053C19C9BDF7AABBA0ABF49B70D27406
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:DarkGate js Pikabot zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
386
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:X117.js
File size:422'591 bytes
SHA256 hash: 35a030b9c4e4bc4f4fbaeb8415fdf4bccd04958216d363a7f0e9caef1df38100
MD5 hash: 22994aee89c4f08e9ac088ddc5bba516
MIME type:text/plain
Signature DarkGate
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Payload URLs
URL
File name
https://www.nortonlifelock.com/fr/fr/privacy/cookies-and-analytics/
JS File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd lolbin obfuscated ping rundll32
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Modifies system certificate store
Runs ping.exe
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments