🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce3f1d357e4e27f1dd49c3c6901e9a9c52179cfbc66824fe1dee181a7896ce9e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ce3f1d357e4e27f1dd49c3c6901e9a9c52179cfbc66824fe1dee181a7896ce9e
SHA3-384 hash: 9d2ba92bf1184c6a49d24e0caa5a39798541ffa49918d63c18c4c9f90b2b7573781d74f7e522b92b1a90689a3f61c0d7
SHA1 hash: a2fd0922e47ca651e1213bd30bf0922067d53ac1
MD5 hash: 6dc286f30c31f186ed724b0c29942352
humanhash: enemy-bluebird-green-freddie
File name:zckgnyuh.bat
Download: download sample
Signature DarkGate
File size:225 bytes
First seen:2023-09-17 06:40:08 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 6:4I5fJQO3glQ/mxiPU7Cwz3HiPUKyGvFxPOwD:4I5FgK+xmYCwzXmT9uwD
TLSH T118D0A73F266F41E6F550AEE920B690D5E0A7248F03680D1C6EE44CCC840844BD50E9D4
Reporter JAMESWT_WT
Tags:bat DarkGate zochao-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
173
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
zckgnyuh.bat
Verdict:
No threats detected
Analysis date:
2023-09-17 13:38:19 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
DarkGate
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Multi AV Scanner detection for domain / URL
Snort IDS alert for network traffic
Uses known network protocols on non-standard ports
Yara detected DarkGate
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1309550 Sample: zckgnyuh.bat Startdate: 17/09/2023 Architecture: WINDOWS Score: 68 32 Snort IDS alert for network traffic 2->32 34 Multi AV Scanner detection for domain / URL 2->34 36 Yara detected DarkGate 2->36 38 Uses known network protocols on non-standard ports 2->38 7 cmd.exe 2 2->7         started        10 TabTip32.exe 2->10         started        process3 file4 24 C:\Users\user\Desktop\zckg.exe, PE32+ 7->24 dropped 12 zckg.exe 2 7->12         started        16 zckg.exe 2 7->16         started        18 Autoit3.exe 1 8 7->18         started        20 conhost.exe 7->20         started        process5 dnsIp6 30 zochao.com 46.173.215.132, 2351, 49715, 49716 GARANT-PARK-INTERNETRU Russian Federation 12->30 26 C:\Users\user\Desktop\Autoit3.exe, PE32 12->26 dropped 28 C:\temp\AutoIt3.exe, PE32 18->28 dropped 22 TabTip32.exe 20->22         started        file7 process8
Verdict:
unknown
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Drops startup file
Executes dropped EXE
Downloads MZ/PE file
Suspicious use of NtCreateUserProcessOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments