PULSE NAME
DarkGate again but... Improved?
WHITE RastaFarEye AlienVault 2024-06-06 Modified: 2024-07-06
333
IOCs
HIGH VOLUME
The report details the latest developments surrounding the DarkGate remote access trojan, including its enhanced capabilities in version 6, the activities of its developer RastaFarEye, and an in-depth analysis of the malware's new features, execution chain, and supported commands. It highlights DarkGate's continued evolution, with the addition of novel techniques like AutoHotKey scripting for payload delivery, as well as the removal of certain functionalities, potentially to maintain a stealthier profile. The analysis underscores the persistent threat posed by this malware and its creators.
Indicators of Compromise (9 / 333 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 985ada16a3f42b15b7ec95ad37aeb4db 2024-06-06
FileHash-MD5 1a036fda50fdada9741afaabdb4485bf MD5 of 1a960526c132a5293e1e02b49f43df1383bf37a0bbadd7ba7c106375c418dad4 2024-06-06
FileHash-MD5 b371387b0b5551c936c94bdf36c2e2f5 MD5 of 038db3b838d0cd437fa530c001c9913a1320d1d7ac0fd3b35d974a806735c907 2024-06-06
FileHash-MD5 e0217823f2f748254b43ede64e422199 MD5 of 2e34908f60502ead6ad08af1554c305b88741d09e36b2c24d85fd9bac4a11d2f 2024-06-06
FileHash-MD5 8a50fabafe78e37d28b30ffe7b8d3f98 MD5 of a4c7584c85cb62c533b09c6efb6e67c71c995eb220364ab947051da20e74db9a 2024-06-06
FileHash-MD5 a9e3f35e404ae681505001afce86b173 MD5 of 6ed1b68de55791a6534ea96e721ff6a5662f2aefff471929d23638f854a80031 2024-06-06
FileHash-MD5 b77d376b82bdd0dd6b5bced9649e7d85 MD5 of b88716e41bac465880a7d43edfc39454c0ab3acfeb0d98ffd7e21cd738af50bf 2024-06-06
FileHash-MD5 e2a20b15c750ef1b6c6e6f545bb7264c MD5 of db860bc4ee3fe65f67fb55985898b66a4187985a6bc2ab95cd6416f2e6d0c2c9 2024-06-06
FileHash-MD5 e93f832ee64b07207c38479dbf3ee767 MD5 of dd7a8b55e4b7dc032ea6d6aed6153bec9b5b68b45369e877bb66ba21acc81455 2024-06-06