# DarkGate

**URL:** <https://community.emergingthreats.net/t/darkgate/1033>\
**Category:** Rule Signatures\
**Created:** [October 13, 2023, 7:16am UTC](https://community.emergingthreats.net/t/darkgate/1033 "2023-10-13T07:16:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [October 13, 2023, 7:16am UTC](https://community.emergingthreats.net/t/darkgate/1033/1 "2023-10-13T07:16:47Z")

</div>

Hi, having decrypted and detonated this sample that was received at the first stage of delivery,

> **[Analysis Archive 3.zip (MD5: 3C0B4B9890C2EFE0515A3F46AF26EF5A) Malicious...](https://app.any.run/tasks/fb92bcf3-3413-4bca-807a-fb002ac48b18/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

I noticed some features of http that can be used for detection. For example, the same user agent, lifetime and what is interesting is the use of a capital letter in the content description:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/de47b859bbf76738b7016e3210beb0966a02522e.png)  
I did not hardcode the port since there is also a request for 8080.  
The body of the request now looks slightly different due to the use of substitution encryption and I always had 102 bytes, the first 32 of which are MD5 from system information. Previously this was an ID parameter. You can also use it at your discretion.  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/52728cce6646c1c97b2d904b2c661bf71abaae98.png)

```auto
pcre: "/^[A-Ma-h]{32}[a-zA-Z0-9=]{6}(.)[a-zA-Z0-9=]{23}\1[a-zA-Z0-9=]{39}$/";

```

> **[regex101: build, test, and debug regex](https://regex101.com/r/bLuHtP/1)**
>
> Regular expression tester with syntax highlighting, explanation, cheat sheet for PHP/PCRE, Python, GO, JavaScript, Java, C#/.NET, Rust.

The proposed rule is as follows:

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] DarkGate Check-In HTTP header";
flow: established, to_server; 

http.method;
content: "POST"; 

http.header;
content: "Keep-Alive: 300"; distance: 0; 
content: "Connection: keep-alive"; distance: 0; 
content: "Content-Type: Application/octet-stream"; distance: 0; 
content: "Content-Length: "; 
byte_test: 0, >, 40, 0, relative, string, dec;
byte_test: 0, <, 750, 0, relative, string, dec;

http.header_names; 
content: "|0d0a|Host|0d 0a|Keep-Alive|0d 0a|Connection|0d 0a|User-Agent|0d 0a|Content-Type|0d 0a|Content-Length|0d 0a 0d 0a|"; startswith;

http.user_agent;
content: "Mozilla/4.0 (compatible|3b| Synapse)"; bsize: 33; 

reference: md5,4d26c05426247f7a4f784967c7b0faa2;
reference: url,app.any.run/tasks/fb92bcf3-3413-4bca-807a-fb002ac48b18;
classtype: command-and-control;
sid: 1; rev: 1;)

```

UP:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/7d2ffcd959e710b95ce08fede7561de9b30abba2.png)  
A colleague just sent me this request, it contains 46 bytes, and of course it matches only the first 32 bytes of the regular expression.

```auto
^[A-Ma-h]{32}

```

> **[Analysis DarkGate-2023-10-12.zip (MD5: C1166B94EFEE9B32E669A84A72B22CDE)...](https://app.any.run/tasks/d0878d08-9996-47da-ad30-1f087406dded/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

UPUP:  
After reviewing the research, I dare to suggest much more content in the data section.

> **[DarkGate - Threat Breakdown Journey](https://0xtoxin.github.io/threat%20breakdown/DarkGate-Camapign-Analysis/)**
>
> Shining a Light on the Hidden Tactics and Techniques Employed by DarkGate

I hope that you will have more traffic to prevent unnecessary checks.  
Cheers, Jane (⌐⊙\_⊙)

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [October 13, 2023, 4:21pm UTC](https://community.emergingthreats.net/t/darkgate/1033/2 "2023-10-13T16:21:31Z")

</div>

Downloaded from triage and launched in any\_run:

> **[Behavioral Report](https://tria.ge/231010-x8d3fsac75/behavioral1)**
>
> Have a look at the Hatching Triage automated malware analysis report for this sample, with a score of 1 out of 10.

> **[Analysis Archive 5.zip (MD5: 0DA46F487E02A3DE64F495D6A4D8DED8) Malicious...](https://app.any.run/tasks/aaa99a00-e5fe-470c-96d2-e5f409218d43/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [October 13, 2023, 10:08pm UTC](https://community.emergingthreats.net/t/darkgate/1033/3 "2023-10-13T22:08:56Z")

</div>

Hey Jane!

Thanks for the sweet sig! The only thing I added was a threshold limit because @malware\_traffic identified traffic that matches your sig and some hosts were creating a frequent amount of requests. Have a great weekend!

> <https://twitter.com/malware_traffic/status/1712839853266628635>

```auto
2048558 - ET MALWARE [ANY.RUN] DarkGate Check-In HTTP Header (POST)

```

Isaac 🧟

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [December 28, 2023, 8:22am UTC](https://community.emergingthreats.net/t/darkgate/1033/4 "2023-12-28T08:22:04Z")

</div>

Hi, can I ask you to add a link to this discussion in the rule 2048558?  
reference:url,[community.emergingthreats.net/t/darkgate/](http://community.emergingthreats.net/t/darkgate/);

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [December 28, 2023, 7:10pm UTC](https://community.emergingthreats.net/t/darkgate/1033/5 "2023-12-28T19:10:20Z")

</div>

Thanks Jane, updated sigs will go out today!

JT
