PULSE NAME
BattleRoyal, DarkGate Cluster Spreads via Email and Fake Browser Updates
WHITE DarkGate AlienVault 2023-12-22 Modified: 2024-01-21
19
IOCs
MEDIUM VOLUME
Throughout the summer and fall of 2023, DarkGate entered the ring competing for the top spot in the remote access trojan (RAT) and loader category. It was observed in use by multiple cybercrime actors and was spread via many methods such as email, Microsoft Teams, Skype, malvertising and fake updates.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DarkGate
Indicators of Compromise (19)
All CVE FileHash-SHA256 domain URL
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2023-36025 2023-12-22
FileHash-SHA256 2f5af97b13b077a00218c60305b4eee5d88d14a9bd042beed286434c3fc6e084 2023-12-22
FileHash-SHA256 7562c213f88efdb119a9bbe95603946ba3beb093c326c3b91e7015ae49561f0f 2023-12-22
FileHash-SHA256 96ca146b6bb95de35f61289c2725f979a2957ce54761aff5f37726a85f2f9e77 2023-12-22
FileHash-SHA256 e2a8a53e117f1dda2c09e5b83a13c99b848873a75b14d20823318840e84de243 2023-12-22
FileHash-SHA256 ea8f893c080159a423c9122b239ec389939e4c3c1f218bdee16dde744e08188f 2023-12-22
FileHash-SHA256 fce452bcf10414ece8eee6451cf52b39211eb65ecaa02a15bc5809c8236369a4 2023-12-22
domain heilee.com 2023-12-22
domain kairoscounselingmi.com 2023-12-22
domain nathumvida.org 2023-12-22
domain searcherbigdealk.com 2023-12-22
domain zxcdota2huysasi.com 2023-12-22
URL http://5.181.159.29:80/Downloads/12.url 2023-12-22
URL http://5.181.159.29:80/Downloads/evervendor.zip/evervendor.exe 2023-12-22
URL http://79.110.62.96:80/Downloads/bye.zip/bye.vbs 2023-12-22
URL http://searcherbigdealk.com:2351/msizjbicvmd 2023-12-22
URL http://searcherbigdealk.com:2351/zjbicvmd 2023-12-22
URL https://heilee.com/qxz3l 2023-12-22
URL https://kairoscounselingmi.com/wp-content/uploads/astra/help/pr-nv28-2023.url 2023-12-22