Indicator of Compromise Search
Bulk Lookup
✦ IPv4 Address ✦ Domain ✦ MD5/SHA1/SHA256 Hash ✦ URL
INDICATOR
e9ad648589aa3e15ce61c6a3be4fc98429581be738792ed17a713b4980c9a4a2
SHA256 ⚠ 10 PULSE HITS
↓ CSV ↓ JSON
75
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH 75/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN LOW MED HIGH CRIT
0 25 50 75 100
OTX
30/30
10 pulses
VIRUSTOTAL
35/35
33/76 detected
ABUSEIPDB
/25
IPv4 only
URLHAUS
10/10
LISTED
General Information
Hashe9ad648589aa3e15ce61c6a3be4fc98429581be738792ed17a713b4980c9a4a2
File TypeFileHash-SHA256
AlienVault OTX Analysis ↗ View on OTX
10
PULSE HITS
Pulse Hits 10
Indicator Type SHA256
Threat Level
ASSOCIATED PULSES
PULSE NAMEDATE
A Social Engineering Tactic to Deploy Malware 2024-07-15
Warning Against Phishing Emails Prompting Execution of Commands via Paste 2024-06-06
Threatfox Recent Additions 2024-11-09
Malicious Object (IP / Hash / URL) 2024-06-28
Weekly OSINT Highlights, 15 July 2024 2024-07-15
VirusTotal Analysis ↗ View on VirusTotal
33/76
DETECTIONS
MALICIOUS
Malicious 33
Suspicious 0
Harmless 0
Undetected 29
Reputation -13
File Name umkglnks
File Type Powershell
File Size 0.2 KB
TOP DETECTIONS
VENDORRESULT
ALYac Trojan.Downloader.PowerShell.Agent
AVG Other:Malware-gen [Trj]
AhnLab-V3 Downloader/PowerShell.Generic
Arcabit Trojan.Agent.GNBP
Avast Other:Malware-gen [Trj]
Avira TR/Dldr.Agent.e9ad64
BitDefender Trojan.Agent.GNBP
CAT-QuickHeal PS.DARKGATE.48747
CTX powershell.trojan.bynoco
Cynet Malicious (score: 99)
URLhaus (abuse.ch) ↗ View on URLhaus
⚠ LISTED
URLHAUS
URLs Found 2
First Seen 2024-05-14
Malware DarkGate
File Type unknown
ASSOCIATED URLs
URL STATUS / TYPE DATE
http://flexiblemaria.com/umkglnks offline
http://91.222.173.186/umkglnks offline