🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf3d542f7aba2d4c00f627d9e0f48bf82acf725a2c6a188a5b2eceea2592c6a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 7


Intelligence 7 IOCs YARA 8 File information Comments

SHA256 hash: bf3d542f7aba2d4c00f627d9e0f48bf82acf725a2c6a188a5b2eceea2592c6a5
SHA3-384 hash: 968a6fd4b65433bbdc5e9278854a4e6fe472df5b5d9f5d59da56a009f51dfdbd42b98b1c891bc1f24787ddd0f8a47619
SHA1 hash: bf1619da25781e5c2210f1649cd8a5e611196795
MD5 hash: 1f75fbe07b3ae2f6337049fbf6359e46
humanhash: hamper-kansas-bluebird-maryland
File name:SIPO-lnk
Download: download sample
Signature DarkGate
File size:2'099 bytes
First seen:2023-09-25 12:19:09 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/octet-stream
ssdeep 24:8adWJCnecYZA8Z1leH+/CxAF7FA1i85+Q64wyIV:8a7JAlebxAzg
TLSH T1D541141536CA7B24D6F1093AC9667324C62AF896D4B2CB0D01D49C8D5855202FD79F39
Reporter JAMESWT_WT
Tags:94-228-169-143 DarkGate lnk

Intelligence


File Origin
# of uploads :
1
# of downloads :
243
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Payload URLs
URL
File name
http://88.119.175.245/WNJD1/iji
LNK File
Behaviour
BlacklistAPI detected
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
cmd evasive lolbin masquerade ping
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Leaks process information
Machine Learning detection for sample
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
Sigma detected: DarkGate
Snort IDS alert for network traffic
Uses known network protocols on non-standard ports
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Windows shortcut file (LNK) contains suspicious command line arguments
Windows shortcut file (LNK) starts blacklisted processes
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1313867 Sample: SIPO-lnk.lnk Startdate: 25/09/2023 Architecture: WINDOWS Score: 100 43 Snort IDS alert for network traffic 2->43 45 Found malware configuration 2->45 47 Antivirus detection for URL or domain 2->47 49 8 other signatures 2->49 8 cmd.exe 1 2->8         started        process3 signatures4 51 Uses ping.exe to sleep 8->51 53 Uses ping.exe to check the status of other devices and networks 8->53 11 cscript.exe 2 8->11         started        15 curl.exe 2 8->15         started        17 conhost.exe 1 8->17         started        19 2 other processes 8->19 process5 dnsIp6 37 94.228.169.143, 2351, 49768, 49769 SSERVICE-ASRU Russian Federation 11->37 39 192.168.2.1 unknown unknown 11->39 55 Windows shortcut file (LNK) starts blacklisted processes 11->55 21 cmd.exe 3 11->21         started        41 88.119.175.245, 49767, 80 IST-ASLT Lithuania 15->41 57 Potential malicious VBS script found (suspicious strings) 15->57 59 Potential malicious VBS script found (has network functionality) 15->59 signatures7 process8 file9 33 C:\vjik\vjik.exe, PE32+ 21->33 dropped 24 vjik.exe 2 21->24         started        27 Autoit3.exe 21->27         started        29 conhost.exe 21->29         started        31 vjik.exe 2 21->31         started        process10 file11 35 C:\vjik\Autoit3.exe, PE32 24->35 dropped
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Runs ping.exe
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:PDF_in_LNK
Author:@bartblaze
Description:Identifies Adobe Acrobat artefacts in shortcut (LNK) files.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments