🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cd158900fe34f41e89d06f73259fc8ab24e2eaefb63c915236bf590788d89da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0cd158900fe34f41e89d06f73259fc8ab24e2eaefb63c915236bf590788d89da
SHA3-384 hash: 7f2e0fe6acce90ce5e88fdeecd0c9095dd1176e79c8392e0983ac7e6f08db1a2339285d9f00ee4f3bbdb4425bd8dd7f1
SHA1 hash: 0a1aa867dfa11e41d48b8e5c3208e9a81311fab9
MD5 hash: 929cd9747f7428c7c19685f37de11e53
humanhash: winter-network-east-minnesota
File name:L8T.vbs
Download: download sample
Signature DarkGate
File size:12'683 bytes
First seen:2023-09-25 12:25:04 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24:cUi/AEwu12cEW8VYzDHCWkqalW9LTK9dPE40Fjd0krr1UQPxwnx:cJnw3W8VYzDHVxaM9iPP0wk31u
TLSH T165424413A1AC0391C1E25338B5C5915EADE94234EB35C972AE29D05D0FA601991E52F7
Reporter JAMESWT_WT
Tags:94-228-169-143 DarkGate vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
143
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Leaks process information
Multi AV Scanner detection for domain / URL
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
Sigma detected: DarkGate
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1313870 Sample: L8T.vbs Startdate: 25/09/2023 Architecture: WINDOWS Score: 100 29 Snort IDS alert for network traffic 2->29 31 Multi AV Scanner detection for domain / URL 2->31 33 Found malware configuration 2->33 35 8 other signatures 2->35 7 wscript.exe 1 2->7         started        process3 dnsIp4 27 94.228.169.143, 2351, 49779, 49780 SSERVICE-ASRU Russian Federation 7->27 37 System process connects to network (likely due to code injection or exploit) 7->37 39 VBScript performs obfuscated calls to suspicious functions 7->39 41 Windows Scripting host queries suspicious COM object (likely to drop second stage) 7->41 11 cmd.exe 3 7->11         started        signatures5 process6 file7 23 C:\vjik\vjik.exe, PE32+ 11->23 dropped 14 vjik.exe 2 11->14         started        17 Autoit3.exe 11->17         started        19 conhost.exe 11->19         started        21 vjik.exe 2 11->21         started        process8 file9 25 C:\vjik\Autoit3.exe, PE32 14->25 dropped
Threat name:
Script-WScript.Trojan.DarkGate
Status:
Malicious
First seen:
2023-09-25 12:26:07 UTC
File Type:
Binary
AV detection:
6 of 23 (26.09%)
Threat level:
  5/5
Result
Malware family:
darkgate
Score:
  10/10
Tags:
family:darkgate stealer
Behaviour
Checks processor information in registry
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Blocklisted process makes network request
Downloads MZ/PE file
DarkGate
Malware Config
C2 Extraction:
http://94.228.169.143
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments