🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5316fc2cb4c54ba46a42e77e9ee387d158f0f3dc7456a0c549f9718b081c6c26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA 5 File information Comments

SHA256 hash: 5316fc2cb4c54ba46a42e77e9ee387d158f0f3dc7456a0c549f9718b081c6c26
SHA3-384 hash: 630e28770311eab311d08d69c10e53c9f66e759318c1f7b143449413ae091b62a339839e566c33d38902bdc965d70ce7
SHA1 hash: 77aaf9c8b944f7178067430aef42f60a2ac1f41c
MD5 hash: 763d557c3e4c57f7d6132a444a930386
humanhash: asparagus-nevada-saturn-berlin
File name:1.zip
Download: download sample
Signature DarkGate
File size:787'241 bytes
First seen:2024-05-27 16:28:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:0sJBgav2i0qpqYBEmjXMNQjzpb57QU8ONZ:0sP7v2WdBEe4UFNZ
TLSH T119F42392C76385B6937BCBADC40B9D092E6372F7C9F1422671F7CAD195F12E8888051E
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:DarkGate zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
425
Origin country :
DE DE
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:script.a3x
File size:560'804 bytes
SHA256 hash: 493fb733897f4c3d7adf01d663e711e2e47240bfdf5b99abd230aa809f43a8cf
MD5 hash: dfa96717b69fa69d264a60b9de36f078
MIME type:application/octet-stream
Signature DarkGate
File name:Autoit3.exe
File size:893'608 bytes
SHA256 hash: 237d1bca6e056df5bb16a1216a434634109478f882d3b1d58344c801d184f95d
MD5 hash: c56b5f0201a3b3de53e561fe76912bfd
MIME type:application/x-dosexec
Signature DarkGate
Vendor Threat Intelligence
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
autoit fingerprint keylogger lolbin overlay packed shell32
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Script
Author:@bartblaze
Description:Identifies AutoIT script. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:SUSP_XORed_Mozilla
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DarkGate

zip 5316fc2cb4c54ba46a42e77e9ee387d158f0f3dc7456a0c549f9718b081c6c26

(this sample)

  
Delivery method
Distributed via web download

Comments