🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a85602ac76f5ee8c7453fc82ecc096dcba85a991a9b094288cdd4d76615e7b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8a85602ac76f5ee8c7453fc82ecc096dcba85a991a9b094288cdd4d76615e7b8
SHA3-384 hash: 9db343b79a29a2c8e941ba6062151613fe27cc0b6e32e08a7f90de81e7cc07043e508c4e16b533a6477b311685e130b2
SHA1 hash: 3b626d8d8d142d5fff76dbb5fe8049314c3a58d4
MD5 hash: ff598b0d4adfc62e4f4afcaf06ee5261
humanhash: hawaii-whiskey-jig-jig
File name:dg.cmd
Download: download sample
Signature DarkGate
File size:233 bytes
First seen:2023-09-28 11:04:55 UTC
Last seen:Never
File type:cmd cmd
MIME type:text/plain
ssdeep 6:4I56hB6uxOoZ3QWQ/mIHYcPs2Wfy3GHYcPsK0c3R:4I56GuvJQf+sYoqfdYor04R
TLSH T1C7D0A74F546B12BFC447EB4A116641CBE407205F4F77CC98974D88C5500F509F454B59
Reporter marqufabi
Tags:AA11 cmd DarkGate ta577

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
72 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1315955 Sample: dg.cmd Startdate: 28/09/2023 Architecture: WINDOWS Score: 72 20 Multi AV Scanner detection for domain / URL 2->20 22 Antivirus detection for URL or domain 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 26 Multi AV Scanner detection for submitted file 2->26 6 cmd.exe 2 2->6         started        process3 file4 16 C:\Users\user\Desktop\wlgt.exe, PE32+ 6->16 dropped 9 wlgt.exe 1 6->9         started        12 conhost.exe 6->12         started        14 wlgt.exe 1 6->14         started        process5 dnsIp6 18 94.228.169.143, 2351 SSERVICE-ASRU Russian Federation 9->18
Threat name:
Script-BAT.Trojan.DarkGate
Status:
Malicious
First seen:
2023-09-28 11:05:06 UTC
File Type:
Text (Batch)
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments