🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae5992df220a719fca79f2322b6f40b43c61ff6e4e55b01183fb088953661537. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ae5992df220a719fca79f2322b6f40b43c61ff6e4e55b01183fb088953661537
SHA3-384 hash: db4fda1bd3c8b59be897d34622ecdee65f8ac6a633efeba12df7e2a5f4f9ffa877c432212200d1715fa9e96259a0d717
SHA1 hash: 558584fa7d79cc989a9313113026ffb7f35b2a32
MD5 hash: 0639a5fe04b2e560d2efbb770c7d11dc
humanhash: london-seventeen-lamp-video
File name:L12T.vbs
Download: download sample
Signature DarkGate
File size:13'739 bytes
First seen:2023-09-25 12:32:07 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24:GZi/AEXz2kNJRQDHCWkqalW9NfnGRXlf9DtkR7z5FWybxJ6fF49+c:bnXzcDHVxaMXU1nkRf3vVc
TLSH T125526353555C0394C1D9133029C4106FDA84C3387BF6D6777958D18527B8858F5E51B6
Reporter JAMESWT_WT
Tags:94-228-169-143 DarkGate vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
141
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Leaks process information
Multi AV Scanner detection for domain / URL
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
Sigma detected: DarkGate
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1313884 Sample: L12T.vbs Startdate: 25/09/2023 Architecture: WINDOWS Score: 100 29 Snort IDS alert for network traffic 2->29 31 Multi AV Scanner detection for domain / URL 2->31 33 Found malware configuration 2->33 35 8 other signatures 2->35 7 wscript.exe 1 2->7         started        process3 dnsIp4 27 94.228.169.143, 2351, 49773, 49774 SSERVICE-ASRU Russian Federation 7->27 37 System process connects to network (likely due to code injection or exploit) 7->37 39 VBScript performs obfuscated calls to suspicious functions 7->39 41 Windows Scripting host queries suspicious COM object (likely to drop second stage) 7->41 11 cmd.exe 3 7->11         started        signatures5 process6 file7 23 C:\vjik\vjik.exe, PE32+ 11->23 dropped 14 vjik.exe 2 11->14         started        17 Autoit3.exe 11->17         started        19 conhost.exe 11->19         started        21 vjik.exe 2 11->21         started        process8 file9 25 C:\vjik\Autoit3.exe, PE32 14->25 dropped
Threat name:
Script-WScript.Trojan.DarkGate
Status:
Malicious
First seen:
2023-09-25 12:31:35 UTC
File Type:
Binary
AV detection:
6 of 23 (26.09%)
Threat level:
  5/5
Result
Malware family:
darkgate
Score:
  10/10
Tags:
family:darkgate stealer
Behaviour
Checks processor information in registry
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Blocklisted process makes network request
Downloads MZ/PE file
DarkGate
Malware Config
C2 Extraction:
http://94.228.169.143
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments