PULSE NAME
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade Smartscreen
WHITE DarkGate AlienVault 2024-04-30 Modified: 2024-05-30
13
IOCs
MEDIUM VOLUME
This report details a novel infection chain associated with DarkGate malware, a Remote Access Trojan (RAT) that exploits the AutoHotkey utility and attempts to bypass Microsoft Defender SmartScreen. The infection begins with an HTML-based entry point or an XLS file, utilizing techniques such as disguising malicious content as legitimate files. The attack chain involves downloading and executing various components, including VBScript, PowerShell scripts, and AutoHotkey scripts, ultimately leading to the execution of the DarkGate payload. The report also highlights the vulnerability CVE-2023-36025 and its exploitation to evade SmartScreen warnings, as well as persistence mechanisms employed by the malware.
Indicators of Compromise (1 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a59a2d3e5dda7aca6ec879263aa42fd3 2024-04-30