PULSE NAME
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade Smartscreen
WHITE DarkGate AlienVault 2024-04-30 Modified: 2024-05-30
13
IOCs
MEDIUM VOLUME
This report details a novel infection chain associated with DarkGate malware, a Remote Access Trojan (RAT) that exploits the AutoHotkey utility and attempts to bypass Microsoft Defender SmartScreen. The infection begins with an HTML-based entry point or an XLS file, utilizing techniques such as disguising malicious content as legitimate files. The attack chain involves downloading and executing various components, including VBScript, PowerShell scripts, and AutoHotkey scripts, ultimately leading to the execution of the DarkGate payload. The report also highlights the vulnerability CVE-2023-36025 and its exploitation to evade SmartScreen warnings, as well as persistence mechanisms employed by the malware.
Indicators of Compromise (13)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a59a2d3e5dda7aca6ec879263aa42fd3 2024-04-30
FileHash-SHA1 312d496ec90eb30d5319307d47bfef602b6b8c6c 2024-04-30
FileHash-SHA256 038db3b838d0cd437fa530c001c9913a1320d1d7ac0fd3b35d974a806735c907 2024-04-30
FileHash-SHA256 10e362e18c355b9f8db9a0dbbc75cf04649606ef96743c759f03508b514ad34e 2024-04-30
FileHash-SHA256 196bb36f7d63c845afd40c5c17ce061e320d110f28ebe8c7c998b9e6b3fe1005 2024-04-30
FileHash-SHA256 1a960526c132a5293e1e02b49f43df1383bf37a0bbadd7ba7c106375c418dad4 2024-04-30
FileHash-SHA256 2b296ffc6d173594bae63d37e2831ba21a59ce385b87503710dc9ca439ed7833 2024-04-30
FileHash-SHA256 2e34908f60502ead6ad08af1554c305b88741d09e36b2c24d85fd9bac4a11d2f 2024-04-30
FileHash-SHA256 4de0e0e7f23adc3dd97d498540bd8283004aa131a59ae319019ade9ddef41795 2024-04-30
FileHash-SHA256 6ed1b68de55791a6534ea96e721ff6a5662f2aefff471929d23638f854a80031 2024-04-30
FileHash-SHA256 897b0d0e64cf87ac7086241c86f757f3c94d6826f949a1f0fec9c40892c0cecb 2024-04-30
FileHash-SHA256 dd7a8b55e4b7dc032ea6d6aed6153bec9b5b68b45369e877bb66ba21acc81455 2024-04-30
domain withupdate.com 2024-04-30