🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2f20d4232da128f7dedc0edf844a92a3e3f6c8a997fab47777a396b0b4a5f53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: f2f20d4232da128f7dedc0edf844a92a3e3f6c8a997fab47777a396b0b4a5f53
SHA3-384 hash: 58f408c8945f04169e5745096d1b0eba5e6d4941522b5e4743276efb3acaa09c92ac06083d9e843a9475de3366260ca0
SHA1 hash: a0a12d6bc2d26267a6041344756b8621e02e1543
MD5 hash: 3e44fef10a982713adb597df2b72c27f
humanhash: edward-mango-victor-batman
File name:script.a3x
Download: download sample
Signature DarkGate
File size:596'624 bytes
First seen:2024-12-14 20:43:31 UTC
Last seen:2024-12-16 13:00:49 UTC
File type:
MIME type:application/octet-stream
ssdeep 12288:I5ar/5ar6gxOhHcM7hsYpzKiQhabk/RTTzcY886Wa:I5ar/5ar/8RcMlsYlKiURTPf6F
TLSH T118C4E0256008F7C5B6774ECBB099C20A62BCA6DDDC4E032E56959BE89734E1D3CF0987
Magika unknown
Reporter NDA0E
Tags:154-216-16-83 a3x DarkGate

Intelligence


File Origin
# of uploads :
2
# of downloads :
147
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Clean
Score:
89.3%
Tags:
autoit emotet
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2024-12-12 15:41:39 UTC
File Type:
Binary
Extracted files:
2
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Script
Author:@bartblaze
Description:Identifies AutoIT script. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings

File information


The table below shows additional information about this malware sample such as delivery method and external references.

DarkGate

f2f20d4232da128f7dedc0edf844a92a3e3f6c8a997fab47777a396b0b4a5f53

(this sample)

Comments