IOC LOOKUP
// SEARCH IP, DOMAIN, HASH, OR URL AGAINST OTX THREAT INTELLIGENCE
Indicator of Compromise Search
✦ IPv4 Address
✦ Domain
✦ MD5/SHA1/SHA256 Hash
✦ URL
INDICATOR
e9ad648589aa3e15ce61c6a3be4fc98429581be738792ed17a713b4980c9a4a2
75
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH
75/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN
LOW
MED
HIGH
CRIT
0
25
50
75
100
OTX
30/30
10 pulses
VIRUSTOTAL
35/35
33/76 detected
ABUSEIPDB
—/25
IPv4 only
URLHAUS
10/10
LISTED
General Information
| Hash | e9ad648589aa3e15ce61c6a3be4fc98429581be738792ed17a713b4980c9a4a2 |
| File Type | FileHash-SHA256 |
AlienVault OTX Analysis
↗ View on OTX
10
PULSE HITS
| Pulse Hits | 10 |
| Indicator Type | SHA256 |
| Threat Level |
ASSOCIATED PULSES
| PULSE NAME | DATE |
|---|---|
| 2024-07-15 | |
| 2024-06-06 | |
| 2024-11-09 | |
| 2024-06-28 | |
| 2024-07-15 |
VirusTotal Analysis
↗ View on VirusTotal
33/76
DETECTIONS
MALICIOUS
| Malicious | 33 |
| Suspicious | 0 |
| Harmless | 0 |
| Undetected | 29 |
| Reputation | -13 |
| File Name | umkglnks |
| File Type | Powershell |
| File Size | 0.2 KB |
TOP DETECTIONS
| VENDOR | RESULT |
|---|---|
| ALYac | Trojan.Downloader.PowerShell.Agent |
| AVG | Other:Malware-gen [Trj] |
| AhnLab-V3 | Downloader/PowerShell.Generic |
| Arcabit | Trojan.Agent.GNBP |
| Avast | Other:Malware-gen [Trj] |
| Avira | TR/Dldr.Agent.e9ad64 |
| BitDefender | Trojan.Agent.GNBP |
| CAT-QuickHeal | PS.DARKGATE.48747 |
| CTX | powershell.trojan.bynoco |
| Cynet | Malicious (score: 99) |
URLhaus (abuse.ch)
↗ View on URLhaus
⚠ LISTED
URLHAUS
| URLs Found | 2 |
| First Seen | 2024-05-14 |
| Malware | DarkGate |
| File Type | unknown |
ASSOCIATED URLs
| URL | STATUS / TYPE | DATE |
|---|---|---|
| http://flexiblemaria.com/umkglnks | offline | — |
| http://91.222.173.186/umkglnks | offline | — |