🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f93bcbccee4e4ec2a28475b2426f63d08ba121f579e6f09a1c85d3cc9633241. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 9f93bcbccee4e4ec2a28475b2426f63d08ba121f579e6f09a1c85d3cc9633241
SHA3-384 hash: 11065d0e4b9c2a38874a2356285861500df35b6ee98583753c6d1a5faa6dd5e01f79739cdd3b3d50aaa0712f1666241f
SHA1 hash: 89266d49a7b4c78a02147d0ddc72b2afba969d7c
MD5 hash: 0c3b85b73db67fe7ce664dfdb5981186
humanhash: cup-sweet-bacon-speaker
File name:runsysclean.png
Download: download sample
Signature DarkGate
File size:1'248'256 bytes
First seen:2023-12-13 14:58:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7cfb5f728219442db8b9b05dd399e043 (1 x DarkGate)
ssdeep 12288:3ZQHpjp3HNogWcmXS1BfzxdWg2dkJ+6F6ziB/iXh3faVUOEhDQfxwtGGzS:YpjhHNoghmiz5OiBcS2OEhsszS
TLSH T10445834BEBB611D5F4BAC139A553222AFC7234A18738D7D792819A0E5B30FE4AD3D740
TrID 72.7% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
13.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
2.5% (.EXE) OS/2 Executable (generic) (2029/13)
2.5% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter abuse_ch
Tags:DarkGate dll exe


Avatar
abuse_ch
DarkGate malspam campaign:
https://adclick.g.doubleclick.net/pcs/click?adurl=//balkarsoftware.cubistech.com
-> https://balkarsoftware.cubistech.com/
--> https://balkarsoftware.cubistech.com/public/build/important/DEC-872667-2023.zip
---> http://5.181.156.243/Downloads/11.url
----> http://5.181.156.243/Downloads/filactery.zip
-----> http://cdn3-adb1.online/abdwufkw/modules/cleanhelper.png
-----> http://cdn3-adb1.online/abdwufkw/modules/legacy_l1.png
-----> http://cdn3-adb1.online/abdwufkw/modules/runsysclean.png

Intelligence


File Origin
# of uploads :
1
# of downloads :
394
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
redline
ID:
1
File name:
https://etiquetaspiura.com/swe/release_ver0_9.rar?search=idm+download+with+crack+64+bit+2023.zip
Verdict:
Malicious activity
Analysis date:
2023-12-12 09:53:01 UTC
Tags:
privateloader evasion loader stealer stealc lumma risepro redline amadey botnet opendir kelihos trojan smoke smokeloader sinkhole raccoon recordbreaker ransomware stop glupteba exela rhadamanthys socks5systemz miner xmrig proxy payload g0njxa

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Gathering data
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Sigma detected: Execute DLL with spoofed extension
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1361493 Sample: runsysclean.png.exe Startdate: 13/12/2023 Architecture: WINDOWS Score: 48 19 Sigma detected: Execute DLL with spoofed extension 2->19 7 loaddll64.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        15 3 other processes 7->15 process5 17 rundll32.exe 9->17         started       
Threat name:
Win64.Trojan.Darkgate
Status:
Suspicious
First seen:
2023-11-13 23:47:08 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
8 of 21 (38.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Unpacked files
SH256 hash:
9f93bcbccee4e4ec2a28475b2426f63d08ba121f579e6f09a1c85d3cc9633241
MD5 hash:
0c3b85b73db67fe7ce664dfdb5981186
SHA1 hash:
89266d49a7b4c78a02147d0ddc72b2afba969d7c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

DarkGate

Executable exe 9f93bcbccee4e4ec2a28475b2426f63d08ba121f579e6f09a1c85d3cc9633241

(this sample)

Comments