🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 141d2a8f40a7d9f0788e2426cac1f4cdbe8f236698077c8a82d92f4e3b94a0fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA 5 File information Comments

SHA256 hash: 141d2a8f40a7d9f0788e2426cac1f4cdbe8f236698077c8a82d92f4e3b94a0fe
SHA3-384 hash: ff37884074ee6c21c6bfd25f45bf73bd60c8959546e3fa10f269ac34b66ad51a874b38e0e277512ecd3842df13fc6869
SHA1 hash: aba71c0590cdbf74340b88812d33022bd28ebbfa
MD5 hash: f95e7acb637e9e2c082d2e8473bdbe36
humanhash: illinois-single-butter-snake
File name:X.xll
Download: download sample
Signature DarkGate
File size:12'288 bytes
First seen:2023-09-25 14:48:30 UTC
Last seen:Never
File type:Excel file xll
MIME type:application/x-dosexec
imphash fd410436ce0407a0a8f79bfce8af0bc3 (25 x DarkGate)
ssdeep 192:uU5z9iLjq2pJk+/qcJklyJOEdRmLsWGQwrgAh:3z9AbJH/IwJOsRh/QwrgC
TLSH T15D42D50E72934CBEC916C176C2FB8771B5FAB4120223972D0AA0D7376EB29A5772DD05
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter proxylife
Tags:51-195-49-233 DarkGate xll

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Behaviour
BlacklistAPI detected
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
anti-debug
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Found malware configuration
Obfuscated command line found
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1313981 Sample: X.xll Startdate: 25/09/2023 Architecture: WINDOWS Score: 68 84 94.228.169.143 SSERVICE-ASRU Russian Federation 2->84 90 Found malware configuration 2->90 92 Yara detected DarkGate 2->92 94 C2 URLs / IPs found in malware configuration 2->94 9 loaddll64.exe 1 2->9         started        11 msiexec.exe 2->11         started        signatures3 process4 file5 14 rundll32.exe 9->14         started        17 rundll32.exe 9->17         started        19 rundll32.exe 9->19         started        25 5 other processes 9->25 76 C:\Windows\Installer\MSI7392.tmp, PE32 11->76 dropped 78 C:\Windows\Installer\MSI6930.tmp, PE32 11->78 dropped 80 C:\Windows\Installer\MSI57C9.tmp, PE32 11->80 dropped 82 C:\Windows\Installer\MSI185D.tmp, PE32 11->82 dropped 21 msiexec.exe 11->21         started        23 msiexec.exe 11->23         started        process6 signatures7 96 Obfuscated command line found 14->96 27 cmd.exe 3 2 14->27         started        29 cmd.exe 17->29         started        31 WerFault.exe 3 9 19->31         started        33 KeyScramblerLogon.exe 21->33         started        37 expand.exe 21->37         started        39 icacls.exe 21->39         started        41 icacls.exe 21->41         started        43 rundll32.exe 25->43         started        45 3 other processes 25->45 process8 file9 47 curl.exe 2 27->47         started        50 conhost.exe 27->50         started        62 2 other processes 27->62 64 4 other processes 29->64 66 C:\Users\user\AppData\Local\...\Autoit3.exe, PE32 33->66 dropped 88 Contains functionality to detect sleep reduction / modifications 33->88 52 Autoit3.exe 33->52         started        68 C:\Users\user\...\keyscrambler.sys (copy), PE32 37->68 dropped 70 C:\Users\user\...\Uninstall.exe (copy), PE32 37->70 dropped 72 C:\Users\...\KeyScramblerLogon.exe (copy), PE32 37->72 dropped 74 7 other files (none is malicious) 37->74 dropped 54 conhost.exe 37->54         started        56 conhost.exe 39->56         started        58 conhost.exe 41->58         started        60 WerFault.exe 17 9 43->60         started        signatures10 process11 dnsIp12 86 51.195.49.233, 49788, 49789, 80 OVHFR France 47->86
Threat name:
Win64.Trojan.DarkGate
Status:
Malicious
First seen:
2023-09-25 14:49:07 UTC
File Type:
PE+ (Dll)
AV detection:
5 of 23 (21.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Loads dropped DLL
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Find_Any_Xll_Files
Author:David Ledbetter @Ledtech3
Description:Find Any XLL File
Rule name:gen_Excel_xll_addin_suspicious
Author:@JohnLaTwC
Description:Detects suspicious XLL add-ins to Excel
Rule name:reverse_http
Author:CD_R0M_
Description:Identify strings with http reversed (ptth)
Rule name:Typical_Malware_String_Transforms
Author:Florian Roth (Nextron Systems)
Description:Detects typical strings in a reversed or otherwise modified form
Reference:Internal Research
Rule name:Typical_Malware_String_Transforms_RID3473
Author:Florian Roth
Description:Detects typical strings in a reversed or otherwise modified form
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments