🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3dee02788568879bc2a3968bd381c0fc5f121bb3c2f46224fd85566282f6837. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d3dee02788568879bc2a3968bd381c0fc5f121bb3c2f46224fd85566282f6837
SHA3-384 hash: 9d0b0929647d609f908c090c277d111e16fc1c13f5d5a843de33181c40d5079521993b65149c75c4cc19dfbe4950c417
SHA1 hash: 3294fa3fd04aada60f5f92a407525ac7f798ce60
MD5 hash: 978ce761a1c7f4b5ebfcd8c9728f1965
humanhash: uncle-fruit-tango-yankee
File name:feb-case_-2024_8114214637.pdf
Download: download sample
Signature DarkGate
File size:167'000 bytes
First seen:2024-02-13 16:19:21 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:iEuym5pR+AgvwWwQAIPAHKeydx5VMPJqzlS+yksO1:iE9m5eh/wdHKeyn5+4pSmse
TLSH T19AF3B0E4DE20AE49E61871F3C63C3691A64DB8277388B3DF64F18615185EDBC60728DB
Reporter k3dg3___
Tags:admin888 DarkGate pdf TA571

Intelligence


File Origin
# of uploads :
1
# of downloads :
703
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
phishing
Label:
Benign
Suspicious Score:
1.4/10
Score Malicious:
14%
Score Benign:
86%
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis
Score:
68 / 100
Signature
Downloads suspicious files via Chrome
Found potential malicious PDF (bad image similarity)
Malicious sample detected (through community Yara rule)
Phishing site detected (based on OCR NLP Model)
Suspicious PDF detected (based on various text indicators)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1391557 Sample: feb-case_-2024_8114214637.pdf Startdate: 13/02/2024 Architecture: WINDOWS Score: 68 37 monitor.clickcease.com 2->37 47 Found potential malicious PDF (bad image similarity) 2->47 49 Malicious sample detected (through community Yara rule) 2->49 51 Suspicious PDF detected (based on various text indicators) 2->51 53 2 other signatures 2->53 9 chrome.exe 23 2->9         started        13 Acrobat.exe 18 67 2->13         started        signatures3 process4 dnsIp5 41 192.168.2.5, 443, 49703, 49710 unknown unknown 9->41 43 192.168.2.6 unknown unknown 9->43 45 239.255.255.250 unknown Reserved 9->45 29 C:\Users\...\invoice20240213102117.zip (copy), Zip 9->29 dropped 15 unarchiver.exe 4 9->15         started        17 chrome.exe 9->17         started        20 AcroCEF.exe 104 13->20         started        file6 process7 dnsIp8 22 7za.exe 2 15->22         started        31 grpt.ca 162.240.8.41, 443, 49733 UNIFIEDLAYER-AS-1US United States 17->31 33 monitor.clickcease.com 20.234.104.33, 443, 49727, 49728 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 17->33 35 7 other IPs or domains 17->35 24 AcroCEF.exe 2 20->24         started        process9 dnsIp10 27 conhost.exe 22->27         started        39 23.54.200.159, 443, 49714 AKAMAI-ASUS United States 24->39 process11
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkGate

pdf d3dee02788568879bc2a3968bd381c0fc5f121bb3c2f46224fd85566282f6837

(this sample)

  
Dropping
3bf99810510c197b9cd6e434d95417515dbc42f94b11bbf9916ec160066eb77e
  
Delivery method
Distributed via e-mail attachment

Comments