🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fa83a1f4b3196a87645d4e71c3a486c7eb433ccb462c85888d5a5dee2abe2e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 15


Intelligence 15 IOCs YARA 11 File information Comments

SHA256 hash: 2fa83a1f4b3196a87645d4e71c3a486c7eb433ccb462c85888d5a5dee2abe2e2
SHA3-384 hash: 8e97e5bd6d29224b3864c8c19e6d81589e9e95fce3f6d9e23f442a008bf2bf28b8317de5179be48c7f472d6c1d6879eb
SHA1 hash: ab8e09f1b836a3bc07a4fd72fc17155f304e8c87
MD5 hash: abdcc4a6d9ebcdb3f832de479bec51e0
humanhash: undress-alanine-kitten-kansas
File name:upd_1916298.exe
Download: download sample
Signature DarkGate
File size:2'695'440 bytes
First seen:2024-10-10 18:11:48 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 8228b51f94e32d919543d0118d0ddc46 (2 x SystemBC, 1 x DarkGate)
ssdeep 49152:Ms8boAvk/rdETXD/j6qYMfnz8xvMOjyPNerGSbR7Wtg2l3ZjH+7DnGdc9iOj:MNboAurdEPjflSb1WtZte7DB
Threatray 3 similar samples on MalwareBazaar
TLSH T15AC5AF13B7C7C073EC929171557ADBA7582D7A20072848CBE2C05E1D68E26D26F36B6F
TrID 47.4% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
25.6% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
8.6% (.EXE) Win64 Executable (generic) (10522/11/4)
5.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
File icon (PE):PE icon
dhash icon e8b249cd4dc982e0 (7 x CoinMiner, 6 x AsyncRAT, 4 x VenomRAT)
Reporter monitorsg
Tags:DarkGate exe Kongtuke signed

Code Signing Certificate

Organisation:Pinchao (Shenzhen) Network Technology Co., Ltd.
Issuer:Certum Extended Validation Code Signing 2021 CA
Algorithm:sha256WithRSAEncryption
Valid from:2024-10-07T08:08:37Z
Valid to:2025-10-07T08:08:36Z
Serial number: 6dffaf77d8c06af0ef1e2a88cfe4360b
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: cb821ec143c163713c13111d49fbc544ca7b7e00950ecbe890cc493d60eb5704
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
monitorsg
hXXps://pushcg[.]com/web-analyzer.js --> hXXps://pushcg[.]com/js.php (landing) --> hXXps://www.contactsyracuse[.]org/wp-admin/js/qrtz.php (exe)

Intelligence


File Origin
# of uploads :
1
# of downloads :
567
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
upd_1916298.exe
Verdict:
Malicious activity
Analysis date:
2024-10-10 18:14:42 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
Powershell Emotet
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm cmd epmicrosoft_visual_cc evasive expand fingerprint lolbin microsoft_visual_cc overlay packed regedit signed
Result
Threat name:
DarkGate, MailPassView
Detection:
malicious
Classification:
troj.spyw.evad
Score:
88 / 100
Signature
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Found malware configuration
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected DarkGate
Yara detected MailPassView
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1531070 Sample: upd_1916298.exe Startdate: 10/10/2024 Architecture: WINDOWS Score: 88 17 91.222.173.80 KICUA-ASGI Ukraine 2->17 19 Found malware configuration 2->19 21 Yara detected DarkGate 2->21 23 Yara detected MailPassView 2->23 25 3 other signatures 2->25 8 upd_1916298.exe 4 2->8         started        signatures3 process4 signatures5 27 Contains functionality to inject threads in other processes 8->27 29 Contains functionality to inject code into remote processes 8->29 31 Contains functionality to detect sleep reduction / modifications 8->31 11 cmd.exe 2 8->11         started        process6 process7 13 WMIC.exe 1 11->13         started        15 conhost.exe 11->15         started       
Threat name:
Win32.Trojan.DarkGate
Status:
Malicious
First seen:
2024-10-10 18:12:12 UTC
File Type:
PE (Exe)
Extracted files:
15
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Verdict:
Malicious
Tags:
darkgate
YARA:
n/a
Unpacked files
SH256 hash:
caff1da272eb993813539a0730607414468ea18e056b2ad56a7ac7429ae99216
MD5 hash:
dabd69e9659c4bc51b23159a5395e9bc
SHA1 hash:
c5dc954c3a3bcfadfd6bd5823a27f8c9eaae3622
Detections:
win_darkgate_w1
SH256 hash:
b7bf0088756e272dc4017e4915709bbdd7e5f97c4c703e26d79412d201a756cf
MD5 hash:
1000fbffdf7bccb5cc9437006fdc904e
SHA1 hash:
df3e3cdd720afbfa2726c6ebce46c2afbd77f4c4
SH256 hash:
2fa83a1f4b3196a87645d4e71c3a486c7eb433ccb462c85888d5a5dee2abe2e2
MD5 hash:
abdcc4a6d9ebcdb3f832de479bec51e0
SHA1 hash:
ab8e09f1b836a3bc07a4fd72fc17155f304e8c87
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DarkGate

Executable exe 2fa83a1f4b3196a87645d4e71c3a486c7eb433ccb462c85888d5a5dee2abe2e2

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::AllocateAndInitializeSid
ADVAPI32.dll::EqualSid
ADVAPI32.dll::FreeSid
ADVAPI32.dll::GetSidSubAuthorityCount
ADVAPI32.dll::GetSidSubAuthority
ADVAPI32.dll::MapGenericMask
COM_BASE_APICan Download & Execute componentsole32.dll::CoAddRefServerProcess
ole32.dll::CoCreateInstance
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AccessCheck
ADVAPI32.dll::AdjustTokenPrivileges
ADVAPI32.dll::CheckTokenMembership
ADVAPI32.dll::DuplicateToken
ADVAPI32.dll::GetFileSecurityW
ADVAPI32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessW
KERNEL32.dll::OpenProcess
ADVAPI32.dll::OpenProcessToken
KERNEL32.dll::CloseHandle
WININET.dll::InternetCloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::GetDriveTypeW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleOutputCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CopyFileW
KERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::CreateFileW
KERNEL32.dll::DeleteFileA
KERNEL32.dll::DeleteFileW
WIN_BASE_USER_APIRetrieves Account InformationADVAPI32.dll::LookupPrivilegeValueW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyExW
ADVAPI32.dll::RegQueryValueExW
ADVAPI32.dll::RegSaveKeyW
WIN_SVC_APICan Manipulate Windows ServicesADVAPI32.dll::OpenSCManagerW
ADVAPI32.dll::OpenServiceW
ADVAPI32.dll::QueryServiceStatus

Comments