🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f93fd92d0ed48dc9f46cb3a1d86cd70843de5ca985ee28c77cf791310d96f435. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f93fd92d0ed48dc9f46cb3a1d86cd70843de5ca985ee28c77cf791310d96f435
SHA3-384 hash: 755939629b217dd385f5a4541b841702963186c5b09454a937012bdaf658aac17431c251c066f2f2090e9f6c99d0b790
SHA1 hash: e235511406047303da86401be08fc56747b31b0a
MD5 hash: d6b61fdb6de92bb6a9bd896232a64232
humanhash: paris-triple-vermont-kilo
File name:M.pdf
Download: download sample
Signature DarkGate
File size:22'740 bytes
First seen:2023-10-10 10:44:57 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 384:Vf2qLD4mWRzERxWIDtAWYCJndLQUHYUfCT6jtwAzrsFA1nYNJj2/haWa92qZluPo:h2qfLSdIDVRntQCwmrd1Y/G+BlAZ8XkG
TLSH T1F1A2C0367E2D3045F086DC2DFE6EB69E469ABA0347EC53D1185E6C0A7448604F683BB7
Reporter JAMESWT_WT
Tags:DarkGate pdf stolenconversation

Intelligence


File Origin
# of uploads :
1
# of downloads :
506
Origin country :
IT IT
Vendor Threat Intelligence
Gathering data
Label:
Benign
Suspicious Score:
1.6/10
Score Malicious:
17%
Score Benign:
83%
Result
Threat name:
DarkGate, MailPassView
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Contains functionality to modify clipboard data
Deletes shadow drive data (may be related to ransomware)
Downloads suspicious files via Chrome
Found malware configuration
Multi AV Scanner detection for domain / URL
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses known network protocols on non-standard ports
Yara detected DarkGate
Yara detected MailPassView
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1322772 Sample: M.pdf Startdate: 10/10/2023 Architecture: WINDOWS Score: 100 71 prestigiousdentistry.com unknown unknown 2->71 73 prestigiousdentistry.com 2->73 75 www.ssl.com 2->75 95 Multi AV Scanner detection for domain / URL 2->95 97 Found malware configuration 2->97 99 Yara detected DarkGate 2->99 101 6 other signatures 2->101 9 KeyScramblerLogon.exe 2 2->9         started        12 chrome.exe 16 2->12         started        16 expand.exe 5 2->16         started        18 4 other processes 2->18 signatures3 process4 dnsIp5 107 Contains functionality to detect sleep reduction / modifications 9->107 20 cmd.exe 1 9->20         started        89 192.168.2.11 unknown unknown 12->89 91 192.168.2.16 unknown unknown 12->91 93 3 other IPs or domains 12->93 61 C:\Users\user\Downloads\Data9.zip (copy), Zip 12->61 dropped 22 unarchiver.exe 4 12->22         started        24 chrome.exe 12->24         started        63 C:\Users\...\KeyScramblerLogon.exe (copy), PE32 16->63 dropped 65 C:\Users\user\...\KeyScramblerIE.dll (copy), PE32 16->65 dropped 67 C:\...\50281decb8b4014e9bc014c95122f9f4.tmp, PE32 16->67 dropped 69 C:\...\073f61f0c089ab40ad3426b352b7cca6.tmp, PE32 16->69 dropped 27 conhost.exe 16->27         started        29 AcroCEF.exe 68 18->29         started        31 conhost.exe 18->31         started        33 conhost.exe 18->33         started        file6 signatures7 process8 dnsIp9 35 Autoit3.exe 20->35         started        38 curl.exe 20->38         started        42 conhost.exe 20->42         started        44 curl.exe 20->44         started        46 cmd.exe 3 2 22->46         started        48 7za.exe 2 22->48         started        83 142.250.176.14, 443, 49783 GOOGLEUS United States 24->83 85 accounts.google.com 142.250.217.141, 443, 49727 GOOGLEUS United States 24->85 87 5 other IPs or domains 24->87 50 AcroCEF.exe 2 29->50         started        process10 dnsIp11 103 Deletes shadow drive data (may be related to ransomware) 35->103 105 Contains functionality to modify clipboard data 35->105 79 prestigiousdentistry.com 162.33.179.65, 2351, 49766, 49769 CORENETUS United States 38->79 81 127.0.0.1 unknown unknown 38->81 59 C:\Users\user\AppData\Local\...\Autoit3.exe, PE32 38->59 dropped 52 msiexec.exe 7 46->52         started        55 conhost.exe 46->55         started        57 conhost.exe 48->57         started        file12 signatures13 process14 dnsIp15 77 www.ssl.com 54.236.82.84, 49755, 80 AMAZON-AESUS United States 52->77
Threat name:
Document-PDF.Trojan.DarkGate
Status:
Malicious
First seen:
2023-10-10 10:45:05 UTC
File Type:
Document
Extracted files:
3
AV detection:
12 of 22 (54.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments