🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7489261cd6b25d6544d0380bd8446748bc6769d2135e286cfeadf995704c2a70. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7489261cd6b25d6544d0380bd8446748bc6769d2135e286cfeadf995704c2a70
SHA3-384 hash: 31fd02b19372c7026c417e8b28fbdf3df5baca4cd4fce12ddb72af6a7067d37809d0505cbc91fb4c144a4197a643e5dc
SHA1 hash: 45f6ca6a1f78e147da8b236a2dfb72e29b90f695
MD5 hash: be9c0eb366e8d875a9641ecf2a7333da
humanhash: nine-berlin-jersey-happy
File name:L10T.vbs
Download: download sample
Signature DarkGate
File size:11'961 bytes
First seen:2023-09-25 12:32:16 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:8Uw2oMnZ78UT+iDuYwUBWDHVxaMnyc2pU:8MZ78Wrut3arca
TLSH T1C23254074AC88142C0F58732628A619FEAC581756736C579396ED43CAB90CA995B12E7
Reporter JAMESWT_WT
Tags:94-228-169-143 DarkGate vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
145
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Leaks process information
Multi AV Scanner detection for domain / URL
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
Sigma detected: DarkGate
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1313882 Sample: L10T.vbs Startdate: 25/09/2023 Architecture: WINDOWS Score: 100 29 Snort IDS alert for network traffic 2->29 31 Multi AV Scanner detection for domain / URL 2->31 33 Found malware configuration 2->33 35 8 other signatures 2->35 7 wscript.exe 1 2->7         started        process3 dnsIp4 27 94.228.169.143, 2351, 49767, 49768 SSERVICE-ASRU Russian Federation 7->27 37 System process connects to network (likely due to code injection or exploit) 7->37 39 VBScript performs obfuscated calls to suspicious functions 7->39 41 Windows Scripting host queries suspicious COM object (likely to drop second stage) 7->41 11 cmd.exe 3 7->11         started        signatures5 process6 file7 23 C:\vjik\vjik.exe, PE32+ 11->23 dropped 14 vjik.exe 2 11->14         started        17 Autoit3.exe 11->17         started        19 conhost.exe 11->19         started        21 vjik.exe 2 11->21         started        process8 file9 25 C:\vjik\Autoit3.exe, PE32 14->25 dropped
Result
Malware family:
darkgate
Score:
  10/10
Tags:
family:darkgate stealer
Behaviour
Checks processor information in registry
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Blocklisted process makes network request
Downloads MZ/PE file
DarkGate
Malware Config
C2 Extraction:
http://94.228.169.143
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments