🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fae85ad14e4729c19a5b1a7195d448a292c5ea4232610cac61ea8d81a9e9d989. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkGate


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fae85ad14e4729c19a5b1a7195d448a292c5ea4232610cac61ea8d81a9e9d989
SHA3-384 hash: fa2d3259215a1e5a75f99e5c0dc04877f5d750b3ec14d7eaa81535308c3fbe817a0cf1c66a89d582c157af7fff99c0c7
SHA1 hash: 0482da98ca50567a03d9677260dc11c95f417168
MD5 hash: bb3c9046b8f9e104308b96cbb603b8fd
humanhash: leopard-alabama-aspen-nebraska
File name:cleanhelper.png
Download: download sample
Signature DarkGate
File size:2'702'592 bytes
First seen:2023-12-13 14:58:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4ef4dae210e27ea2bf03dfd3ffcd5282 (1 x DarkGate)
ssdeep 49152:ZrwzuNY02yiFrnySHv1JXziYrA1OnWTYkEquCAiT2RLa/r/fHc/d/xHq/z/Xwoc8:ZrwzZtf9HvpxUJMvN+
TLSH T1F5C56CC9F3D2509FC62B8936C69BE7B27730B81801549D6A32C4EB3B1D6AFC15D19B24
TrID 58.9% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
16.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
10.7% (.EXE) Win64 Executable (generic) (10523/12/4)
5.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
2.1% (.ICL) Windows Icons Library (generic) (2059/9)
Reporter abuse_ch
Tags:DarkGate dll exe


Avatar
abuse_ch
DarkGate malspam campaign:
https://adclick.g.doubleclick.net/pcs/click?adurl=//balkarsoftware.cubistech.com
-> https://balkarsoftware.cubistech.com/
--> https://balkarsoftware.cubistech.com/public/build/important/DEC-872667-2023.zip
---> http://5.181.156.243/Downloads/11.url
----> http://5.181.156.243/Downloads/filactery.zip
-----> http://cdn3-adb1.online/abdwufkw/modules/cleanhelper.png
-----> http://cdn3-adb1.online/abdwufkw/modules/legacy_l1.png
-----> http://cdn3-adb1.online/abdwufkw/modules/runsysclean.png

Intelligence


File Origin
# of uploads :
1
# of downloads :
404
Origin country :
CH CH
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug cobalt control finger keylogger lolbin masquerade overlay packed shell32
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Sigma detected: Execute DLL with spoofed extension
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1361492 Sample: cleanhelper.png.exe Startdate: 13/12/2023 Architecture: WINDOWS Score: 48 34 Sigma detected: Execute DLL with spoofed extension 2->34 8 loaddll64.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        16 14 other processes 8->16 process5 18 rundll32.exe 10->18         started        20 WerFault.exe 12->20         started        22 WerFault.exe 16 14->22         started        24 WerFault.exe 16 16->24         started        26 WerFault.exe 16 16->26         started        28 WerFault.exe 16->28         started        30 2 other processes 16->30 process6 32 WerFault.exe 23 16 18->32         started       
Threat name:
Win64.Trojan.ScarletFlash
Status:
Malicious
First seen:
2023-12-13 14:59:06 UTC
File Type:
PE+ (Dll)
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
fae85ad14e4729c19a5b1a7195d448a292c5ea4232610cac61ea8d81a9e9d989
MD5 hash:
bb3c9046b8f9e104308b96cbb603b8fd
SHA1 hash:
0482da98ca50567a03d9677260dc11c95f417168
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

DarkGate

Executable exe fae85ad14e4729c19a5b1a7195d448a292c5ea4232610cac61ea8d81a9e9d989

(this sample)

Comments