🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09934e32acfde19375912fa8b1cc70dfbffc1df06cb4de3dc4bbbce28e5c4c2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RaccoonStealer


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 09934e32acfde19375912fa8b1cc70dfbffc1df06cb4de3dc4bbbce28e5c4c2d
SHA3-384 hash: 8a9c2d802876cd9ee666ace133495f6c4f05e452e0f1e311fcc071a2a7d99670b97fbb127d1110c545c94ca57e2324a7
SHA1 hash: ff7ec5c06131ecf3917c5cd05c6da7fa6e7926cc
MD5 hash: a9104b092d9351e0b43dc99ef52f8c77
humanhash: sierra-pluto-muppet-montana
File name:lingiang.hta
Download: download sample
Signature RaccoonStealer
File size:57'610 bytes
First seen:2023-10-08 23:36:40 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 768:8aZEVIpcuJUALTCbLcSopP48LXeCr6I2Zqj6t:8wEVIppJUALGboRPnXNYqj6t
TLSH T15543F3E30E44AAE837D55B2EF66CA83933B11DB7143BAB946092D51F1312405C9EFCB9
Reporter 1ZRR4H
Tags:DarkGate hta RaccoonStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
CL CL
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Result
Threat name:
DarkGate, MailPassView, Raccoon Stealer
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Deletes shadow drive data (may be related to ransomware)
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (suspicious strings)
Snort IDS alert for network traffic
Suspicious command line found
Suspicious powershell command line found
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses known network protocols on non-standard ports
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Yara detected DarkGate
Yara detected MailPassView
Yara detected Raccoon Stealer v2
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1321870 Sample: lingiang.hta Startdate: 09/10/2023 Architecture: WINDOWS Score: 100 85 vn.abcxzy.com unknown unknown 2->85 87 vn.abcxzy.com 2->87 107 Snort IDS alert for network traffic 2->107 109 Multi AV Scanner detection for domain / URL 2->109 111 Found malware configuration 2->111 113 10 other signatures 2->113 14 mshta.exe 1 2->14         started        17 Autoit3.exe 2->17         started        signatures3 process4 signatures5 139 Suspicious powershell command line found 14->139 141 Very long command line found 14->141 19 powershell.exe 12 14->19         started        143 Deletes shadow drive data (may be related to ransomware) 17->143 22 cmd.exe 17->22         started        24 cmd.exe 17->24         started        process6 signatures7 115 Potential malicious VBS script found (suspicious strings) 19->115 117 Very long command line found 19->117 119 Suspicious command line found 19->119 121 Found suspicious powershell code related to unpacking or dynamic code loading 19->121 26 cmd.exe 1 19->26         started        29 conhost.exe 19->29         started        123 Deletes shadow drive data (may be related to ransomware) 22->123 31 WerFault.exe 22->31         started        process8 signatures9 129 Suspicious powershell command line found 26->129 131 Wscript starts Powershell (via cmd or directly) 26->131 133 Very long command line found 26->133 135 Tries to delay execution (extensive OutputDebugStringW loop) 26->135 33 powershell.exe 20 19 26->33         started        36 powershell.exe 15 26->36         started        38 conhost.exe 26->38         started        process10 dnsIp11 83 216.238.110.110, 49712, 8080 RAZOR-PHLUS United States 33->83 40 wscript.exe 1 33->40         started        43 Acrobat.exe 60 33->43         started        process12 signatures13 125 Wscript starts Powershell (via cmd or directly) 40->125 127 Windows Scripting host queries suspicious COM object (likely to drop second stage) 40->127 45 cmd.exe 40->45         started        47 AcroCEF.exe 75 43->47         started        process14 process15 49 Autoit3.exe 45->49         started        53 curl.exe 45->53         started        56 conhost.exe 45->56         started        58 curl.exe 45->58         started        60 AcroCEF.exe 47->60         started        dnsIp16 77 C:\temp\AutoIt3.exe, PE32 49->77 dropped 103 Deletes shadow drive data (may be related to ransomware) 49->103 105 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 49->105 62 cmd.exe 49->62         started        67 cmd.exe 49->67         started        69 cmd.exe 49->69         started        89 vn.abcxzy.com 65.20.75.41, 2351, 49716, 49724 CP-ASDE United States 53->89 91 127.0.0.1 unknown unknown 53->91 79 C:\Users\user\AppData\Local\...\Autoit3.exe, PE32 53->79 dropped file17 signatures18 process19 dnsIp20 99 vn.abcxzy.com 62->99 81 C:\ProgramData\bdgbbfe\Autoit3.exe, PE32 62->81 dropped 101 Deletes shadow drive data (may be related to ransomware) 62->101 71 cmd.exe 62->71         started        74 cmd.exe 67->74         started        file21 signatures22 process23 dnsIp24 93 216.238.101.101, 80 RAZOR-PHLUS United States 71->93 95 65.20.77.120, 80 CP-ASDE United States 71->95 97 2 other IPs or domains 71->97 137 Deletes shadow drive data (may be related to ransomware) 74->137 signatures25
Threat name:
Document-HTML.Trojan.Darkgate
Status:
Malicious
First seen:
2023-10-08 23:37:06 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Result
Malware family:
raccoon
Score:
  10/10
Tags:
family:raccoon botnet:86a7f0a811515f6c66191dc766ec7b2f stealer
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Drops startup file
Executes dropped EXE
Blocklisted process makes network request
Downloads MZ/PE file
Raccoon
Raccoon Stealer payload
Suspicious use of NtCreateUserProcessOtherParentProcess
Malware Config
C2 Extraction:
http://216.238.101.101:80/
http://194.87.31
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:QbotStuff
Author:anonymous

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments