🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 933fbda1ca7c4a52adbb48d038c8ba5ed5ee411d1096b2222ca383ca6d96a6bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA 36 File information Comments 1

SHA256 hash: 933fbda1ca7c4a52adbb48d038c8ba5ed5ee411d1096b2222ca383ca6d96a6bc
SHA3-384 hash: 549c320fe373d2026f2df70f16e0eba1547d6a8e0138cce23c63640ce54226f82c42509d04289e91fb4e7c4144ed6d77
SHA1 hash: 8156b216fd7059dbd1046b943ade1b0a6a64de1b
MD5 hash: ab3c640841540414d0583e744693da75
humanhash: california-nevada-kilo-coffee
File name:178.33.94.35.zip
Download: download sample
Signature DarkGate
File size:2'077'374 bytes
First seen:2024-08-18 21:39:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:yTZOriGAFEogB1WLgelipZlroMB6n1FI1VVkeXeKZZD:eOri6JULdiFExXuDXl9
TLSH T177A53359283FF65AED2E4EBAFC0A7C4D07FBA955751EC644113CF8441A4BE6A301C2A3
TrID 63.6% (.MAFF) Mozilla Archive Format (gen) (7000/1/1)
36.3% (.ZIP) ZIP compressed archive (4000/1)
Reporter s1dhy
Tags:DarkGate zip


Avatar
s1dhy
Multiple Darkgate samples downloaded from version6dkgate.duckdns[.]org

Intelligence


File Origin
# of uploads :
1
# of downloads :
235
Origin country :
DE DE
File Archive Information

This file archive contains 49 file(s), sorted by their relevance:

File name:nws.png
File size:29'594 bytes
SHA256 hash: 7aa5a3ad27daf394346f9022e21c67e85a27aaa72a3d9dcbdcbc0d165fbc45da
MD5 hash: beb3af8884d5c1aa04de55f77cafcecc
MIME type:image/png
Signature DarkGate
File name:accessibility.xml
File size:668 bytes
SHA256 hash: 2f7b427ae6cdbbfbb8ea7ce9fa470e8a027230ad8ddf1a54eb5084b9fed53da1
MD5 hash: 49b377a447a1f6c6040f20b0e452b31d
MIME type:application/octet-stream
Signature DarkGate
File name:provider_paths.xml
File size:556 bytes
SHA256 hash: f80b31f1c202ff91d95298771cb0d8cf6d96d9c342f0d8adfa2e01d6bfac9190
MD5 hash: 9c83abadc9a9c3bcee97cc2f0cf1f894
MIME type:application/octet-stream
Signature DarkGate
File name:notification_action.xml
File size:1'060 bytes
SHA256 hash: 12ac08d6c67e514220fa27d67b239ffdc71283c3281420390e517e300f6d841a
MD5 hash: 5a0701238ee8640aa97adbea44afeb3e
MIME type:application/octet-stream
Signature DarkGate
File name:goglnobak.png
File size:13'904 bytes
SHA256 hash: ef534795bebad6c01584e38223099e73b9880cbd1566894ae6db11f2d7e14f37
MD5 hash: 8bff0cea74e49cfab90252435c38b589
MIME type:image/png
Signature DarkGate
File name:MANIFEST.MF
File size:5'766 bytes
SHA256 hash: cdcafab2c22ca40f5e7763647bdd9f1ae1b370ee33cf87e9cf51c83ebccdc1e4
MD5 hash: 8396abd571d660a85a24efcecbc68d78
MIME type:text/plain
Signature DarkGate
File name:liquidz64
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Signature DarkGate
File name:bonev68.xml
File size:452 bytes
SHA256 hash: 89c3a8cbf308deb0231f986a92c3fe4c9f4f8f71e004d42314a92b60cb6b4b38
MD5 hash: 588645405f02a65a988de0cdc966b0c6
MIME type:application/octet-stream
Signature DarkGate
File name:shape.xml
File size:680 bytes
SHA256 hash: d8c73210a854c7f617240b7300d5d8240411b9909274e8750b4fcedbd5888f01
MD5 hash: b0d1c096a68dbbb962527c14da866374
MIME type:application/octet-stream
Signature DarkGate
File name:classes2.dex
File size:140 bytes
SHA256 hash: e0aeaa1d698e1d1149ffdcf116e7b3e98b3a3097814e01718c80caaee147b7ae
MD5 hash: 6ceb6f454e31d55f7a0c4bf3000b26f9
MIME type:application/octet-stream
Signature DarkGate
File name:notification_action_tombstone.xml
File size:1'236 bytes
SHA256 hash: 1e24b358138b860023d817f3636b8830c0fdd353e68a13c4eda14f827a04dea5
MD5 hash: c20de6d18b60b5148d2ca58e4e6f9e72
MIME type:application/octet-stream
Signature DarkGate
File name:skinicon.png
File size:100 bytes
SHA256 hash: 67618fdaa085253410592dbe82f1789b41070f69fe3148639e50112f6f0cd2ad
MD5 hash: 9a2bfd2a014257a0d6db2d2f792d0489
MIME type:image/png
Signature DarkGate
File name:launcher.vbs
File size:354 bytes
SHA256 hash: 0dfbfd429529d8ce274ecd35f1e8faa55e7bcfc16a93968fe6fbb109f7955654
MD5 hash: 4cb1a7cb21db24824c33bfd995dae81d
MIME type:text/plain
Signature DarkGate
File name:notification_bg.xml
File size:644 bytes
SHA256 hash: 6b91d0d34e4f1adeac438965b1eccdf5947fa5baa58a605a0124ce7102169fc0
MD5 hash: aae7027a13562fcff5b8d5edeb55fd57
MIME type:application/octet-stream
Signature DarkGate
File name:notify_panel_notification_icon_bg.png
File size:99 bytes
SHA256 hash: 6598a6e07bd8876909eb886ebb75529bb91fa8677e0e5718ac38eb2962833da3
MD5 hash: a0c2ca0fe4db91be21cc897f237c9373
MIME type:image/png
Signature DarkGate
File name:notification_tile_bg.xml
File size:380 bytes
SHA256 hash: bc3fcfcd19c637c14918f7ac5359ba025f5bd56da47d042557ef1f09519e344e
MD5 hash: 7e3e2ba348d88861fe343b5861acf60c
MIME type:application/octet-stream
Signature DarkGate
File name:resources.arsc
File size:57'384 bytes
SHA256 hash: fb7dcc9a422296d3a75ef851c4300fbdeb015b350f93caebc9eda996cace3ed7
MD5 hash: a8438a624916690edd0b885fed77c40f
MIME type:application/octet-stream
Signature DarkGate
File name:notification_bg_normal.9.png
File size:221 bytes
SHA256 hash: 559bf783d765c02338e97952bdc9c6689c7ff99090b8c9813369118da8b080f0
MD5 hash: bf3a10daa260ba3f4cd3325b94f75cf7
MIME type:image/png
Signature DarkGate
File name:stubbed.exe
File size:444'928 bytes
SHA256 hash: 8a93eabf56949eb69dc5c81a39645fec215d967d126751a8bb72e2f90a3c41c7
MD5 hash: 32779bb4eda0b1834dc50d88f4930c3e
MIME type:application/x-dosexec
Signature DarkGate
File name:notification_bg_low_pressed.9.png
File size:251 bytes
SHA256 hash: 3b79243ef0228d6a5b66a25416c980ba9620851c879093a9da4feb84b33961a0
MD5 hash: 668d179f248f33343f95b98ba90066a1
MIME type:image/png
Signature DarkGate
File name:KEY.RSA
File size:1'384 bytes
SHA256 hash: 3dcd95271157209bc08351da4d1f8cef66f3b3fbdce86361c0a0906f6299cfdd
MD5 hash: 4982ca807716a2236c413370f0242972
MIME type:application/octet-stream
Signature DarkGate
File name:notification_template_part_time.xml
File size:448 bytes
SHA256 hash: 140892996617907a25143a05010c258d195895ef24124968c5d96ee4f002db48
MD5 hash: 96e0fa60d603cd36ce82567ab93891d9
MIME type:application/octet-stream
Signature DarkGate
File name:index.html
File size:360 bytes
SHA256 hash: 67b9aee949ea0c9afd1e408a78bda767ac38fe2386626abe844dca4c754425f1
MD5 hash: 6eb00be1c3f69a79915a5099511e7eee
MIME type:text/html
Signature DarkGate
File name:notification_icon_background.xml
File size:436 bytes
SHA256 hash: bd0b1ef0196e4f9e7e2a4e201f7b179c2a321b92cbba4920d3ae76a3c3468eff
MD5 hash: 1102e8d5abe32a4455c7b4ac95b57694
MIME type:application/octet-stream
Signature DarkGate
File name:notification_template_custom_big.xml
File size:2'456 bytes
SHA256 hash: 377b00e9c638db134d9b1ac62ca259fbbabb293d84b2612346f8cf97ba297666
MD5 hash: 0d125326418c5a79ae8078f45366bf17
MIME type:application/octet-stream
Signature DarkGate
File name:adminrights.xml
File size:488 bytes
SHA256 hash: 7f676fbabe4b0270140bfa7b0c964e2956aec31d6f9815fb34480ff186691a23
MD5 hash: f009e659f80c4f83ef177f2a37ad87a3
MIME type:application/octet-stream
Signature DarkGate
File name:update.bat
File size:6'621 bytes
SHA256 hash: 20c3a5b1c87627e9e016494b806273230f5023cf12d2c0e29eceecb7b8a6d3b6
MD5 hash: 97b7c88a02b2a5214d742b7ed50f4544
MIME type:text/plain
Signature DarkGate
File name:splits0.xml
File size:8'396 bytes
SHA256 hash: 9f84463450dbede8470173799c9f724b6f902d6f71e456d8c6b4fb68387965ad
MD5 hash: d4ea7ab9b31b8e24f228ef51beeea782
MIME type:application/octet-stream
Signature DarkGate
File name:sqlite3.dll
File size:500'088 bytes
SHA256 hash: b98bacd2a12a4912acb8e6c8b4447c19b811672f5d6c43048b62c9e273c863d4
MD5 hash: 05ec7e9dee5c43b659d7843f6eb462a2
MIME type:application/octet-stream
Signature DarkGate
File name:notification_bg_normal_pressed.9.png
File size:246 bytes
SHA256 hash: 4a24d2180b1dfd48e40bd675e2b601fdb26099732b4700678984f59cbd67d417
MD5 hash: fa054cbba957c42a29528e848242f4fd
MIME type:image/png
Signature DarkGate
File name:notification_template_icon_group.xml
File size:996 bytes
SHA256 hash: 2cfae751d9e138e95eb569029e8e86f50e4a711a6f4d1198db8cf3f0c7e145c5
MD5 hash: c17ca3cbc14e8ffc356b3c144a279d06
MIME type:application/octet-stream
Signature DarkGate
File name:pidgin.exe
File size:110'856 bytes
SHA256 hash: 8292226e43a1aced9d38e2bdfb14cebabc12f9aa0a76ebdc47971eac026407f2
MD5 hash: c283b2379ea584aab52abee0844b02a0
MIME type:application/x-dosexec
Signature DarkGate
File name:notification_action_background.xml
File size:1'352 bytes
SHA256 hash: a914572b50a97e84b9ff0cf481ea178d15b669cd2e78e15b6a5e586cba5bf11a
MD5 hash: e229967856155d9616b13f24d2baf15a
MIME type:application/octet-stream
Signature DarkGate
File name:notification_template_part_chronometer.xml
File size:448 bytes
SHA256 hash: e8a9c6785c1b4b35e4ac77511f56e5347cfafcbe94f05379384b9545a6229497
MD5 hash: f63c8e517f95cbc38eaa3616467fd7e1
MIME type:application/octet-stream
Signature DarkGate
File name:freespace.png
File size:155 bytes
SHA256 hash: f7820f8f9a8138d3cbc0cee6d75025e7c483b7f6355640571ddd3dd695c605db
MD5 hash: 7eae9ba292f06654056bb9d91d4cb2cc
MIME type:image/png
Signature DarkGate
File name:bakaro.png
File size:477 bytes
SHA256 hash: 3e6051eefccd1935db1d3bcaaca1538148d23ddf6eeb76d055b4c12877238666
MD5 hash: 531a21c44b66e195a1029b29b2aa1e79
MIME type:image/png
Signature DarkGate
File name:flogin.xml
File size:5'000 bytes
SHA256 hash: f2eb37c6285ac837b406e21943cbc83d66f280478176cd5988346894181e5ee0
MD5 hash: 7afb87a98e048d72e196b7ce4cba7b90
MIME type:application/octet-stream
Signature DarkGate
File name:bsl.png
File size:141'338 bytes
SHA256 hash: d5e56cc88da946d72b845bdd6aa3ec24a4c1cfc30a4a113bbd158cdc25d076db
MD5 hash: a443a43869dbec6b9928b408218ff17d
MIME type:image/png
Signature DarkGate
File name:update.zip
File size:363'719 bytes
SHA256 hash: 5d6f71d05f493b0f94a2a3a5e89aa328b2b19f7f3221989ed44256ed7cf9c31a
MD5 hash: 52d1c5d8f77927b8774979e4c382703b
MIME type:application/zip
Signature DarkGate
File name:AndroidManifest.xml
File size:28'344 bytes
SHA256 hash: 24f65e09ec5b8b9d1470f2088f4c2177cdc97dbdde28ceb4320ed356775a10cc
MD5 hash: 64d79093ef816b25db1a3c73a8eda797
MIME type:application/octet-stream
Signature DarkGate
File name:glogin.xml
File size:3'968 bytes
SHA256 hash: a1d55d6dc653791d43eeca55413966fc75bfb4fa4d0d1456e7f0ca2a1365032b
MD5 hash: 0fb767de3f6df1b49ee0f842a0979560
MIME type:application/octet-stream
Signature DarkGate
File name:notification_bg_low.xml
File size:644 bytes
SHA256 hash: d320bbe6082ce1ff0ca5fa1060c325142e8356690d0dfcb1079a8b6fa0b4d5a2
MD5 hash: bc9e3db2fea23a0fb82b3a9e8a4f03a8
MIME type:application/octet-stream
Signature DarkGate
File name:tranclat.png
File size:12'466 bytes
SHA256 hash: 9f1ef3f4280479484734770e25f42c05c21ce4a9444f73a3f92448c392b076bd
MD5 hash: 29cd12f6585c7c922fc6575be5ae3c29
MIME type:image/png
Signature DarkGate
File name:KEY.SF
File size:5'893 bytes
SHA256 hash: 0c4f09db7ce40504585239d98898e4489215f830aa734bc4d9f6cd7e8ee7c63a
MD5 hash: 988ebee8d4db011de76dedb27f49d3bf
MIME type:text/plain
Signature DarkGate
File name:incestm67.xml
File size:908 bytes
SHA256 hash: fb174f349942f2b680c11ad8f3410e75d52f36c70bd82c0924bd2703b2aeff41
MD5 hash: 0f4017e3210ef2605b238a152533593b
MIME type:application/octet-stream
Signature DarkGate
File name:libssp-0.dll
File size:90'624 bytes
SHA256 hash: 7786e9e3c7fe54f52b54e4bb922ef569ad68dc14f4096d530824556975e0f462
MD5 hash: 1f521e8b258d2b09f66fb8c940452b72
MIME type:application/x-dosexec
Signature DarkGate
File name:notification_bg_low_normal.9.png
File size:221 bytes
SHA256 hash: 3e09afa21c45372c035598c017c8fb405a6d678e6cb84dc857581cb3b40e482d
MD5 hash: 3d4e903880e581df0dff44a4cc07c65b
MIME type:image/png
Signature DarkGate
File name:wib.xml
File size:584 bytes
SHA256 hash: 2b83d63e8a434045d60a43df5520460e0bfc8ea99a4f789ed52f2f84cbb95d49
MD5 hash: 4cb7d84efdca70b3faf2c5ad45529629
MIME type:application/octet-stream
Signature DarkGate
File name:loading.xml
File size:476 bytes
SHA256 hash: 2a4d1c73a9c007f1755d209c885e55b93c107646bca1c5dec16d92c908b94699
MD5 hash: 57cd931a94ce88efa25abed9a9cc891d
MIME type:application/octet-stream
Signature DarkGate
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
Execution Generic Infostealer Network
Threat name:
Win32.Spyware.SpyNote
Status:
Malicious
First seen:
2024-08-18 21:40:06 UTC
File Type:
Binary (Archive)
Extracted files:
141
AV detection:
29 of 38 (76.32%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Script
Author:@bartblaze
Description:Identifies AutoIT script. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:Borland
Author:malware-lu
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:DarkGate
Author:enzok
Description:DarkGate Payload
Rule name:DbatLoader
Author:Harish Kumar P
Description:Yara Rule to Detect DbatLoader
Rule name:INDICATOR_SUSPICIOUS_EXE_References_AdsBlocker_Browser_Extension_IDs
Author:ditekSHen
Description:Detect executables referencing considerable number of Ads blocking browser extension IDs
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MALWRE_Win_DarkGate
Author:ditekSHen
Description:Detects DarkGate infostealer and coinminer
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:Sectigo_Code_Signed
Description:Detects code signed by the Sectigo RSA Code Signing CA
Reference:https://bazaar.abuse.ch/export/csv/cscb/
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Windows_Trojan_DarkGate_07ef6f14
Author:Elastic Security
Rule name:Win_DarkGate
Author:0xToxin
Description:DarkGate Strings Decryption Routine
Rule name:win_darkgate_w1
Author:enzok
Description:DarkGate Payload
Rule name:win_darkgate__tmt
Rule name:win_onliner_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.onliner.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropped by
DarkGate
  
Delivery method
Other

Comments



Avatar
Kasibe commented on 2024-09-09 14:36:22 UTC

SpyNote