🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb2434f22b2fb7801cdd2b81e2b28a41a2beb2dc72b3d07ffec0e0f120c7a4bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: bb2434f22b2fb7801cdd2b81e2b28a41a2beb2dc72b3d07ffec0e0f120c7a4bf
SHA3-384 hash: 745df989290a0b2c7f5b3acb03d44356629d7bf2e6085a8be7eb8a5f47585b21d555f80add525f9ac78a1538dc4ad9af
SHA1 hash: 00190f05968b9abb08003d2806ca6c0654023199
MD5 hash: 518c222c82014bb0978b04885d5d0c5a
humanhash: jig-virginia-burger-stairway
File name:aa.xll
Download: download sample
Signature DarkGate
File size:51'200 bytes
First seen:2023-09-21 16:18:42 UTC
Last seen:2023-09-21 17:13:31 UTC
File type:Excel file xll
MIME type:application/x-dosexec
imphash eb3f1099640d7d708a3042408447c005 (4 x DarkGate)
ssdeep 1536:MUK23Jsm6Nh5wF3s8KjrtN/5TqRGiNwmU2x0Q0Y:cCsNh5wF3s8KXHRTviNnAPY
Threatray 2 similar samples on MalwareBazaar
TLSH T19D33275BF39311FAC16BC17846A7A372B670BC114131AFAED790FB342E25E94AA1D701
TrID 44.4% (.EXE) Win64 Executable (generic) (10523/12/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter proxylife
Tags:94-228-169-123 DarkGate xll

Intelligence


File Origin
# of uploads :
2
# of downloads :
207
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://basicwear-international.eu/mest/
Verdict:
No threats detected
Analysis date:
2023-09-21 16:22:35 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malicious
File Type:
Office Add-Ins - Suspicious
Behaviour
BlacklistAPI detected
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
anti-debug
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Drops PE files to the user root directory
Found malware configuration
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1312483 Sample: aa.xll Startdate: 21/09/2023 Architecture: WINDOWS Score: 68 91 94.228.169.143 SSERVICE-ASRU Russian Federation 2->91 99 Found malware configuration 2->99 101 Yara detected DarkGate 2->101 103 C2 URLs / IPs found in malware configuration 2->103 10 loaddll64.exe 1 2->10         started        12 msiexec.exe 2->12         started        signatures3 process4 file5 15 rundll32.exe 1 10->15         started        19 rundll32.exe 2 10->19         started        21 rundll32.exe 10->21         started        25 3 other processes 10->25 85 C:\Windows\Installer\MSI923F.tmp, PE32 12->85 dropped 87 C:\Windows\Installer\MSI57A5.tmp, PE32 12->87 dropped 23 msiexec.exe 12->23         started        process6 file7 89 C:\Users\Public\me.exe, PE32+ 15->89 dropped 97 Drops PE files to the user root directory 15->97 27 me.exe 19 15->27         started        29 me.exe 1 19->29         started        31 WerFault.exe 20 9 21->31         started        34 KeyScramblerLogon.exe 23->34         started        38 expand.exe 23->38         started        40 icacls.exe 23->40         started        42 icacls.exe 23->42         started        44 WerFault.exe 9 25->44         started        46 rundll32.exe 2 25->46         started        signatures8 process9 dnsIp10 48 cmd.exe 1 27->48         started        50 cmd.exe 3 2 29->50         started        95 192.168.2.1 unknown unknown 31->95 75 C:\Users\user\AppData\Local\...\Autoit3.exe, PE32 34->75 dropped 105 Contains functionality to detect sleep reduction / modifications 34->105 52 Autoit3.exe 34->52         started        77 C:\Users\user\...\keyscrambler.sys (copy), PE32 38->77 dropped 79 C:\...\f5d9d7d905e78043bc759786f6fbf0c3.tmp, PE32 38->79 dropped 81 C:\...\da9b4bc6bcf85940a4da97d2ee85ab63.tmp, PE32 38->81 dropped 83 13 other files (none is malicious) 38->83 dropped 54 conhost.exe 38->54         started        56 conhost.exe 40->56         started        58 conhost.exe 42->58         started        file11 signatures12 process13 process14 60 curl.exe 2 48->60         started        63 conhost.exe 48->63         started        65 timeout.exe 1 48->65         started        67 conhost.exe 50->67         started        69 curl.exe 1 50->69         started        71 timeout.exe 1 50->71         started        73 msiexec.exe 50->73         started        dnsIp15 93 5.42.77.33, 49712, 49716, 80 RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU Russian Federation 60->93
Threat name:
Win64.Trojan.Darkgate
Status:
Malicious
First seen:
2023-09-21 16:19:06 UTC
File Type:
PE+ (Dll)
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
darkgate
Score:
  10/10
Tags:
family:darkgate discovery stealer
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Delays execution with timeout.exe
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
NSIS installer
Enumerates physical storage devices
Drops file in Windows directory
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
DarkGate
Malware Config
C2 Extraction:
http://94.228.169.143
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Find_Any_Xll_Files
Author:David Ledbetter @Ledtech3
Description:Find Any XLL File
Rule name:gen_Excel_xll_addin_suspicious
Author:@JohnLaTwC
Description:Detects suspicious XLL add-ins to Excel

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DarkGate

Excel file xll bb2434f22b2fb7801cdd2b81e2b28a41a2beb2dc72b3d07ffec0e0f120c7a4bf

(this sample)

  
Delivery method
Distributed via web download

Comments