🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78173877885f7d0b28cb13b16a034b4849ccc2c3f2b7a92ed8ed71e2956248c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 78173877885f7d0b28cb13b16a034b4849ccc2c3f2b7a92ed8ed71e2956248c8
SHA3-384 hash: 0ec44d32085195525901a8d14cb640fb0bcac63a22d992f77fe3f189844a7bf8a648e0420aab274a8646004bf1c252ac
SHA1 hash: 6cd29a7130cc56b28e84bb92ff847dbff7b9880e
MD5 hash: 998323d209e25f000ed01a0e7cf2f4ea
humanhash: maine-comet-fish-speaker
File name:Report-15.vbs
Download: download sample
Signature DarkGate
File size:17'225 bytes
First seen:2023-10-10 16:56:30 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 384:SzE0ig4KR/aQsKHWMnkf+cTPgKekvj27vmJYs:AJHHXkfNEKekvq7eJz
TLSH T1EA723F52ED075D38E047DAE7694F50F1C43200A3B654A1A4BE8CF6E95B83725B8FE262
Reporter malwarelabnet
Tags:DarkGate vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
CA CA
Vendor Threat Intelligence
Result
Threat name:
DarkGate, MailPassView
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Contains functionality to modify clipboard data
Deletes shadow drive data (may be related to ransomware)
Found malware configuration
Potential malicious VBS script found (suspicious strings)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses known network protocols on non-standard ports
VBScript performs obfuscated calls to suspicious functions
Yara detected DarkGate
Yara detected MailPassView
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1323113 Sample: Report-15.vbs Startdate: 10/10/2023 Architecture: WINDOWS Score: 100 30 prestige-castom.com unknown unknown 2->30 32 vintagecarsforlife.com unknown unknown 2->32 34 prestige-castom.com 2->34 36 Found malware configuration 2->36 38 Yara detected DarkGate 2->38 40 Yara detected MailPassView 2->40 42 5 other signatures 2->42 8 wscript.exe 3 2->8         started        signatures3 process4 signatures5 44 VBScript performs obfuscated calls to suspicious functions 8->44 11 cmd.exe 1 8->11         started        process6 process7 13 Autoit3.exe 16 11->13         started        16 curl.exe 2 11->16         started        20 curl.exe 2 11->20         started        22 conhost.exe 11->22         started        dnsIp8 46 Deletes shadow drive data (may be related to ransomware) 13->46 48 Contains functionality to modify clipboard data 13->48 26 prestige-castom.com 162.33.179.65, 2351, 49716, 49719 CORENETUS United States 16->26 28 127.0.0.1 unknown unknown 16->28 24 C:\Users\user\AppData\Local\...\Autoit3.exe, PE32 16->24 dropped file9 signatures10
Threat name:
Script-WScript.Trojan.Tnega
Status:
Malicious
First seen:
2023-10-10 16:57:08 UTC
File Type:
Text (VBS)
AV detection:
5 of 21 (23.81%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Checks processor information in registry
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Blocklisted process makes network request
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments