🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e12752127453904ac2e3cdbd3772e5334e7f0265c5d16d7e08f9e876c0145ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 7e12752127453904ac2e3cdbd3772e5334e7f0265c5d16d7e08f9e876c0145ea
SHA3-384 hash: 652d3287c7e9d6ecbe9c1c85bcd1eaa1376fca72516ec5162a365bd0ac0cba861528b47825b7a3017e53feb83858868d
SHA1 hash: b0025034f01a38a3102fd03c5c8d5f79a0b4891d
MD5 hash: c82d6d64b4fc7d55a62c4149bc54b370
humanhash: island-romeo-sierra-purple
File name:roamingkiller.zip
Download: download sample
Signature DarkGate
File size:2'028'192 bytes
First seen:2024-08-17 06:27:21 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/octet-stream
ssdeep 49152:R4tfFfcyNtMmDjedW6ECW5sDnLVKtLn+j:RgFf3Jf6ENqnxcW
TLSH T1649533F4C18F5C17BCB23A15F21BEBB6FC29D8C24258D58705698BD5483BF9CA091764
Reporter T33r41n
Tags:DarkGate msi

Intelligence


File Origin
# of uploads :
1
# of downloads :
201
Origin country :
ID ID
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.Malgent
Status:
Malicious
First seen:
2024-05-05 16:27:23 UTC
File Type:
Binary
Extracted files:
18
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Command and Scripting Interpreter: AutoIT
Enumerates connected drives
Modifies file permissions
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropping
DarkGate

Comments