🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45386816654e229126f004100621360ea2501c4b71eab09bddfd97785b3c42e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 45386816654e229126f004100621360ea2501c4b71eab09bddfd97785b3c42e2
SHA3-384 hash: 911efbd0fa78ab3de5e08fa725f305bd78d3b9b780fa4e9a208bb3bfd76bae64b49ddc90b5886b2f61f25901ea886dcf
SHA1 hash: 3417776a79553cf0136e8f890b789806272badf4
MD5 hash: 268007760567310e9a6abfa2edbce02e
humanhash: nine-texas-beryllium-arizona
File name:attach#6081-18-03-2024.xlsx
Download: download sample
Signature DarkGate
File size:58'894 bytes
First seen:2024-03-18 16:53:01 UTC
Last seen:2024-03-18 18:52:17 UTC
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 768:bnaZ932qpaOKFSGOJdGvoZCPAUJ1YxBardD2TSWGdCIKD13zegYN1T/wRI:gJ2u4OPKIxoEuDKNzexToRI
TLSH T10A43D048E78BCCE1C660A576444F17797735A180CBC0FE4E8A78EC720BC67A52F5A8D9
TrID 60.1% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
30.9% (.ZIP) Open Packaging Conventions container (17500/1/4)
7.0% (.ZIP) ZIP compressed archive (4000/1)
1.7% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter James_inthe_box
Tags:DarkGate xlsx

Intelligence


File Origin
# of uploads :
2
# of downloads :
2'716
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
45386816654e229126f004100621360ea2501c4b71eab09bddfd97785b3c42e2.xlsx
Verdict:
No threats detected
Analysis date:
2024-03-18 16:55:20 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changing an executable file
Using the Windows Management Instrumentation requests
Creating a window
Сreating synchronization primitives
Searching for the window
Infecting executable files
Result
Verdict:
Suspicious
File Type:
OOXML Excel File
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
explorer lolbin macros-on-open
Label:
Malicious
Suspicious Score:
9.1/10
Score Malicious:
91%
Score Benign:
9%
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.expl.evad
Score:
100 / 100
Signature
Contains functionality to register a low level keyboard hook
Detected suspicious Microsoft Office reference URL
Document exploit detected (process start blacklist hit)
Document Viewer accesses SMB path (likely to steal NTLM hashes or to download payload)
Installs new ROOT certificates
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Opens network shares
Sigma detected: Legitimate Application Dropped Executable
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Suspicious Microsoft Office Child Process
Snort IDS alert for network traffic
Suspicious execution chain found
Uses certutil -decode
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1411203 Sample: attach#6081-18-03-2024.xlsx Startdate: 18/03/2024 Architecture: WINDOWS Score: 100 36 Snort IDS alert for network traffic 2->36 38 Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros) 2->38 40 Detected suspicious Microsoft Office reference URL 2->40 42 4 other signatures 2->42 8 EXCEL.EXE 54 15 2->8         started        11 explorer.exe 2->11         started        13 explorer.exe 3 2->13         started        process3 signatures4 50 Opens network shares 8->50 52 Document Viewer accesses SMB path (likely to steal NTLM hashes or to download payload) 8->52 15 wscript.exe 1 8->15         started        process5 signatures6 54 Wscript starts Powershell (via cmd or directly) 15->54 56 Windows Scripting host queries suspicious COM object (likely to drop second stage) 15->56 58 Suspicious execution chain found 15->58 60 Opens network shares 15->60 18 powershell.exe 12 8 15->18         started        process7 dnsIp8 32 buassinnndm.net 198.167.201.153, 49162, 49163, 49164 CYBERDYNELR Saint Kitts and Nevis 18->32 34 192.168.2.255, 137, 138 unknown unknown 18->34 44 Uses certutil -decode 18->44 46 Installs new ROOT certificates 18->46 22 AutoHotkey.exe 18->22         started        25 certutil.exe 2 18->25         started        28 attrib.exe 18->28         started        signatures9 process10 file11 48 Contains functionality to register a low level keyboard hook 22->48 30 C:\gmli\AutoHotkey.exe, PE32 25->30 dropped signatures12
Threat name:
Document-Excel.Trojan.Heuristic
Status:
Malicious
First seen:
2024-03-18 16:53:00 UTC
File Type:
Document
Extracted files:
14
AV detection:
6 of 24 (25.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments