🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82e5409032e3d8d85390982fe99a86aa9f313f3c7b68c1e3fb4541d81fe9e24a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 82e5409032e3d8d85390982fe99a86aa9f313f3c7b68c1e3fb4541d81fe9e24a
SHA3-384 hash: 333a64d6c87d49d28f234f7ba9ceb90c0f93eec3f8355ff433faf972b5cac3cd1a63d976d592d1ed1724105e0feb61fd
SHA1 hash: 66e0867a6f86fe25cf6773e58a8ff9ebb34fa36e
MD5 hash: 317f213abccd88f7b240063e2bf9995d
humanhash: iowa-comet-nineteen-lima
File name:1.vbs
Download: download sample
Signature DarkGate
File size:3'792 bytes
First seen:2023-09-22 16:39:03 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:application/octet-stream
ssdeep 24:Te9j+Pz0xr+QhKF6tkta+s6OD56SdsO9QZPXQnXngboF3ztzqMKJOIZytANYL4:T6T+D4kU36OD5BUyXg8ptzWJOIZyaYL
TLSH T1FA71D8BB42CC0192D9E623F2000735F265BEC034F258D271F0BC83A027172ACE1D81B9
Reporter malwarelabnet
Tags:94-228-169-143 DarkGate vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
165
Origin country :
CA CA
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (suspicious strings)
Sigma detected: DarkGate
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1313188 Sample: 1.vbs Startdate: 23/09/2023 Architecture: WINDOWS Score: 100 29 Snort IDS alert for network traffic 2->29 31 Multi AV Scanner detection for domain / URL 2->31 33 Found malware configuration 2->33 35 6 other signatures 2->35 7 wscript.exe 1 2->7         started        process3 dnsIp4 27 94.228.169.143, 2351, 49713, 49714 SSERVICE-ASRU Russian Federation 7->27 37 System process connects to network (likely due to code injection or exploit) 7->37 39 VBScript performs obfuscated calls to suspicious functions 7->39 41 Windows Scripting host queries suspicious COM object (likely to drop second stage) 7->41 11 cmd.exe 3 7->11         started        signatures5 process6 file7 23 C:\bpzs\bpzs.exe, PE32+ 11->23 dropped 14 bpzs.exe 2 11->14         started        17 Autoit3.exe 11->17         started        19 conhost.exe 11->19         started        21 bpzs.exe 2 11->21         started        process8 file9 25 C:\bpzs\Autoit3.exe, PE32 14->25 dropped
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-09-22 16:40:05 UTC
File Type:
Binary
AV detection:
1 of 38 (2.63%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments