MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkCloud


Vendor detections: 16


Intelligence 16 IOCs YARA 18 File information Comments

SHA256 hash: 3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8
SHA3-384 hash: 566882951d3a8d67799ba24209f9d4db1c2505d8e90417389d407fdfb3e77669c286b9d0b76fd7ea4a7023e7e152fcf9
SHA1 hash: ea84c911eb757ad3539fd78f17fbfc6b318f7526
MD5 hash: 11d850eda27a2fa55baee567dc8bc12e
humanhash: fish-shade-moon-skylark
File name:3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8
Download: download sample
Signature DarkCloud
File size:833'536 bytes
First seen:2025-05-09 13:00:50 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'454 x Formbook, 12'202 x SnakeKeylogger)
ssdeep 24576:8pgKrCMyxR3MmsYcLIIViyT3172VIegIjzhunhW:MZ2R6VnrMRvYn
Threatray 3'686 similar samples on MalwareBazaar
TLSH T1160502087202F95FC5534FB74E62DEB05A345DBA960BC6035AC76DDFB85EB868E00392
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:DarkCloud exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
319
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Comprobante de transferencia adjunto.eml
Verdict:
Malicious activity
Analysis date:
2025-04-17 18:50:34 UTC
Tags:
attachments attc-unc susp-attachments stealer evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
virus micro msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Creating a file
Creating a file in the %AppData% subdirectories
Reading critical registry keys
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Sending an HTTP GET request
Creating a window
Stealing user critical data
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
crypt obfuscated obfuscated packed packed packer_detected vbnet
Result
Threat name:
DarkCloud
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Sigma detected: Silenttrinity Stager Msbuild Activity
Tries to harvest and steal browser information (history, passwords, etc)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes or reads registry keys via WMI
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected DarkCloud
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1685427 Sample: DQq8UbLI5n.exe Startdate: 09/05/2025 Architecture: WINDOWS Score: 100 47 showip.net 2->47 49 shed.dual-low.s-part-0043.t-0009.t-msedge.net 2->49 51 5 other IPs or domains 2->51 69 Found malware configuration 2->69 71 Malicious sample detected (through community Yara rule) 2->71 73 Antivirus detection for URL or domain 2->73 75 10 other signatures 2->75 9 DQq8UbLI5n.exe 7 2->9         started        13 svchost.exe 2->13         started        signatures3 process4 dnsIp5 39 C:\Users\user\...\oUaNDTX.exe:Zone.Identifier, Unknown 9->39 dropped 41 C:\Users\user\AppData\Roaming\oUaNDTX.exe, Unknown 9->41 dropped 43 C:\Users\user\AppData\Local\...\tmp49EE.tmp, Unknown 9->43 dropped 45 C:\Users\user\AppData\...\DQq8UbLI5n.exe.log, Unknown 9->45 dropped 77 Uses schtasks.exe or at.exe to add and modify task schedules 9->77 79 Writes to foreign memory regions 9->79 81 Allocates memory in foreign processes 9->81 83 2 other signatures 9->83 16 oUaNDTX.exe 5 9->16         started        19 powershell.exe 23 9->19         started        21 powershell.exe 23 9->21         started        23 2 other processes 9->23 55 127.0.0.1 unknown unknown 13->55 file6 signatures7 process8 dnsIp9 57 Antivirus detection for dropped file 16->57 59 Writes to foreign memory regions 16->59 61 Allocates memory in foreign processes 16->61 63 Injects a PE file into a foreign processes 16->63 26 MSBuild.exe 16->26         started        29 schtasks.exe 16->29         started        65 Loading BitLocker PowerShell Module 19->65 31 conhost.exe 19->31         started        33 conhost.exe 21->33         started        53 showip.net 162.55.60.2, 49681, 49682, 80 ACPCA United States 23->53 67 Writes or reads registry keys via WMI 23->67 35 conhost.exe 23->35         started        signatures10 process11 signatures12 85 Tries to harvest and steal browser information (history, passwords, etc) 26->85 37 conhost.exe 29->37         started        process13
Threat name:
Win32.Infostealer.Generic
Status:
Suspicious
First seen:
2025-04-17 16:42:12 UTC
File Type:
PE (.Net Exe)
Extracted files:
8
AV detection:
23 of 37 (62.16%)
Threat level:
  5/5
Result
Malware family:
darkcloud
Score:
  10/10
Tags:
family:darkcloud discovery execution stealer
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Command and Scripting Interpreter: PowerShell
DarkCloud
Darkcloud family
Unpacked files
SH256 hash:
3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8
MD5 hash:
11d850eda27a2fa55baee567dc8bc12e
SHA1 hash:
ea84c911eb757ad3539fd78f17fbfc6b318f7526
SH256 hash:
bfd24b494e12138526338d33e6c3f90f6675424fad34a619d84355dce5f9cd9f
MD5 hash:
631f3f9301a6f97fd7f28baf4576eda2
SHA1 hash:
1ac920087b010ece64be8530ff9b241de3bb3b6c
Detections:
darkcloudstealer INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore INDICATOR_SUSPICIOUS_EXE_TelegramChatBot INDICATOR_SUSPICIOUS_EXE_CC_Regex MALWARE_Win_DarkCloud
SH256 hash:
cbf27e5571803b74b9628d1736abf86992680725c95cb276e7c72ca2c65da971
MD5 hash:
2954fab674961ddd79ca9a4fe2b093cf
SHA1 hash:
fe1b918c4f9cddad4102694dc17dad556af97723
Detections:
darkcloudstealer INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore INDICATOR_SUSPICIOUS_EXE_TelegramChatBot INDICATOR_SUSPICIOUS_EXE_CC_Regex MALWARE_Win_DarkCloud
SH256 hash:
dcfcd16fbf0511d3f2b3792e5493fa22d7291e4bb2efbfa5ade5002a04fc2cab
MD5 hash:
073a17b6cfb1112c6c838b2fba06a657
SHA1 hash:
a54bb22489eaa8c52eb3e512aee522320530b0be
SH256 hash:
6022804a18f6595973d02aa325e343ba13be413ca20fedd9e94eefce29de8746
MD5 hash:
8ead54b743f5d8d5ae7f6e1795394800
SHA1 hash:
0e7b03a738ae573237ecf984c64c8a74ef32488d
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
94e46ff7e9ff4cc19b485e59aa01bdf8e2e323847c0fb6528f8e8bb55ce81e71
MD5 hash:
332d742221b51016f5284dceedef1d1c
SHA1 hash:
176467623b7010403ce2aa0a583937e373e7c3d0
SH256 hash:
8635ca154b89b2024f294ea2e49d8c8eaba8f1e94871d212ffaa0cd060207a6f
MD5 hash:
e6a106a90f0f930d751cbb6478fc33ff
SHA1 hash:
45564aa207f7c4285f28deafd2a723c87c3f9f78
SH256 hash:
6b116ce624a0b3484dc15d8d58509e2ea2d6cb0933489928649c453b94b0249f
MD5 hash:
b6f532e7227ad44f9ee0be9b8088b460
SHA1 hash:
5422e616d8df08512bb9d1ec8b0e199113e85392
SH256 hash:
c86f74bde741e4cd45cd3d18e6f72d1bed0db7e51907ca544666759e9243992e
MD5 hash:
a339d3d449235cae2beb66cc129d55de
SHA1 hash:
60d1302bce795f3c833615f15688c42f64df8516
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
31bc97a1ab065dd497e772032a542190b899ea5b995edebe86595d7d6dfe06ad
MD5 hash:
533b08152584b64a607845c10c751ff8
SHA1 hash:
6486d16b037ac1a3b7241c554f17df34a707511e
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
Parent samples :
bd11383a61346123c23e3959b9f9e2f85ff23f9b09a88256f4c67c26356a980a
3489a2eab1c57d0eee2ce6e5773e1f4f53ee6e5d8963e0099efc7e190d0c2f1c
e6fe2241c57847a4911e325b6d3692839f9033de0c99ddeabd47e8d62022bcd1
faac3d9161a1d539ec42986280eeab6246b71c427fa176a239562c110448a1c1
074efb70a49088638d0e62cc3637a75627afe9286c3f2d024e78ea9f247582fe
23808b7d7764dc5d702974b63f7b15c92d86e0ca95826edb47b2f919d911b9c8
6036a28c74493ce0e6d87a468959a047011d2e6cf63807d9a3d154b8642d7e65
be838fc4e67ed12838f4d0ec554524d54e80a03a3949ced4edfb958edbcb24b8
4867fd993605221960bb0289477ed3a14727ed81cc14b8da8b61e3f509d097f5
37da80758e0acd6993e9a2639927c5bcbf8388526fa93168a9b70f6619775df9
c06298e32597bfdf3374174b8f458169df5d561280f5aa11fd25868c67a5de9f
a90bca8c1f6a63cc34a896eb3883428fab6fb6b4aca385ac917fdafcdbf9e774
048ae81730730b45b67054c6ca4e83d727c07b14568397bc95ef51e4825e830d
ea8cce203873c762292f08d1d461a3f38521f1e77bc175dd68b4fef76ceabd19
bda5884e1a65b59d74d3366608a4841111d43d0b6a865879736f5179bac1bcf3
fa1cfaafe2029ee02035b899a389916cb02bac4270d3f438be0a5013f170e420
f2414faf44fac2135ccce1d5fe5c3a53ec3fcde7ad295e2e112af373b02da086
03a317048a5778933751cbf631e08c5b870ec2da45d74466c53f460a603d7d42
4d59b35375d85ca3dd06c76cedea67009a37075e179d0ae192b9412b24bec974
54f50cdad3e5039d3207566e1b9de6e16913993ba2aa711e6f91a68e093ed9c4
b9ee87f239e3ee4599d666b1b755f97ab4c2ab45507654ec1485f9d60af710ca
c6424a8d5558035680e043348443092f2ad0295be323d2848f6509639990ea28
278854f2430457153ca438c78d14f2469083281da9ec3baebad93d4dd7a3c125
1e98340b6b95bf8c7f96f0b3825473f914d71f78dd2a3032f1f8c3b78c118223
8ef48c6c52f5fed10b8d7c572da9d657ba1fb813a04356de5a47055e9b1250ef
9c100d322eee0b94c9d996c7bc1167df02a820d34dd4b5ee30748d331b064595
c7de64db20145557f5070412a4e15d4d2a00487974e8fce0f4bc3ee42999bd04
5b97cd88bfb20b5d92d426072bc581d159fea064159872e983805bd2c225e64c
ff5bccafd98ba9bd46b459881d752902794630c891dd98764fc1b51cb25a1aed
800a4bab620b5a0c3e184b76cd1a345d5b74b7754fd6aa10a37742e801c5d850
b91da8b8d9a3a5da385a0bde839b80d16824f485746b75597e9236a96d7b2445
3bed682a9298367059c63e05f0b565dbad9f5959302f239c00a92eb3aeb16d67
a7ae95af3a74e706c7a3370b351ba6070b7470e5b6fae98b59fc2612d1e4376e
3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8
07a74041ab09d6e30042a163e518da8c70f644924d576a268c981baad87a19ae
699abf03b319292d82d86e3669e6e0e59ed5d704064c56212dbcbde4a8d8fadd
8b3c3e6d8c540773529da82ad7c28265d6a5462e96d1f07a7781dd76c6004ac5
e0ec24c22840b9435a7fcba35fcc9fc13b371abea00ead5ef60ec9f0893630b3
013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec
51fde361f93dc3702ed13354d064da8422188f3e1b06d9c9b04951da07d89cb8
dc4e9ca482f2b9e15b04d70b2be7ecb6ec63a40e83da756503cbb1b9fbe023c1
5f8549af42d110a594441941f439b1a7c1d58ec75cf7acf9c9bdfcea75dadedd
SH256 hash:
542ea5c8022d1b4c851c94d31b6aa9e0bfdeeff844ba30be006b961319638a02
MD5 hash:
00626a80a4c68025ef3aa1bea361b004
SHA1 hash:
9f2321cb797c2fa70af7acb9e86f94f190f0f23e
Detections:
darkcloudstealer INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore INDICATOR_SUSPICIOUS_EXE_TelegramChatBot INDICATOR_SUSPICIOUS_EXE_CC_Regex MALWARE_Win_DarkCloud
SH256 hash:
23b3abfd7c664cc0b3397c80290eb4df5172b26e06e6415eb63be2db9c930edd
MD5 hash:
e27496902e3696f818ae4195264de184
SHA1 hash:
cae30601d5e864c0d5fe5614c11f4a2072883b98
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
b7ebdc039e5ce763736376e36576d48ba7f334086c37ff886dcee7af70b36a42
MD5 hash:
7d779a8c9f6e22b49e558dd2460aca42
SHA1 hash:
e214bdb2e941d41b68c3fe44198cc9995a823bdd
SH256 hash:
86fa3b49aa3e88ac924e36f31fe87c03118d10dc94fb48f5c5e2da2ce42187df
MD5 hash:
83d9e6f4490fd9bb621d7085360f6f09
SHA1 hash:
e48e5fac1cd2b912fb145027379b1506631c5842
SH256 hash:
b37378e7df09d6cd6b248b3a7c75e32aaf53fa10148aeb2732786abe7bf8ac26
MD5 hash:
a6339fd8b31742b0c0e66fab7d916629
SHA1 hash:
fbcbd3cbc85135934cd12d420d6a75ef04869b0d
SH256 hash:
b71a73cccede7bc6819c9da4c2e683992b34a56f375bd11b18c862eaeb5925cc
MD5 hash:
b0a185373938758564aac2a552a06050
SHA1 hash:
11d485d65a9b71a64c2f396dc1a1a8a0640c1446
SH256 hash:
48a6638c56d3c2ae8dce965951a5d029f184196570e5b30ab95bfc969f30a7f6
MD5 hash:
a4a7ed867f61bb0a4d3ea5fae3fb628c
SHA1 hash:
7bad5b951d43237f4ff6dbe328f85749d6d546c3
Detections:
darkcloudstealer INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore INDICATOR_SUSPICIOUS_EXE_TelegramChatBot INDICATOR_SUSPICIOUS_EXE_CC_Regex MALWARE_Win_DarkCloud
SH256 hash:
3b75425895af4ae3186b36277553641e37ca1d620ae18d68e40d13351b54de6a
MD5 hash:
94d1531b52774dce52a89e33646d5b1d
SHA1 hash:
29bf887b025b97bd7a9e1e261852ba824234a625
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_CC_Regex
Author:ditekSHen
Description:Detects executables referencing credit card regular expressions
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore
Author:ditekSHen
Description:Detects executables containing SQL queries to confidential data stores. Observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
Author:ditekSHen
Description:Detects executables using Telegram Chat Bot
Rule name:MALWARE_Win_DarkCloud
Author:ditekSHen
Description:Detects DarkCloud infostealer
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:ProtectSharewareV11eCompservCMS
Author:malware-lu
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:Windows_Trojan_DarkCloud_9905abce
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments