DarkGate - Drop DarkGate Loader In C:\Temp Directory


Description

Detects attackers attempting to save, decrypt and execute the DarkGate Loader in C:\temp folder.

Query · sigma

selection_filename_suffix:
  TargetFilename|contains: :\temp\
  TargetFilename|endswith:
  - .au3
  - \autoit3.exe
selection_image_suffix:
  Image|contains: :\temp\
  Image|endswith:
  - .au3
  - \autoit3.exe
condition: 1 of selection_*

Known false positives

  • Unlikely legitimate usage of AutoIT in temp folders.
Raw source DarkGate - Drop DarkGate Loader In C:\Temp Directory · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: DarkGate - Drop DarkGate Loader In C:\Temp Directory
id: df49c691-8026-48dd-94d3-4ba6a79102a8
status: test
description: Detects attackers attempting to save, decrypt and execute the DarkGate Loader in C:\temp folder.
references:
    - https://www.bleepingcomputer.com/news/security/hackers-exploit-windows-smartscreen-flaw-to-drop-darkgate-malware/
    - https://www.trendmicro.com/en_us/research/24/c/cve-2024-21412--darkgate-operators-exploit-microsoft-windows-sma.html
author: Tomasz Dyduch, Josh Nickels
date: 2024-05-31
tags:
    - attack.execution
    - attack.t1059
    - detection.emerging-threats
logsource:
    category: file_event
    product: windows
detection:
    selection_filename_suffix:
        TargetFilename|contains: ':\temp\'
        TargetFilename|endswith:
            - '.au3'
            - '\autoit3.exe'
    selection_image_suffix:
        Image|contains: ':\temp\'
        Image|endswith:
            - '.au3'
            - '\autoit3.exe'
    condition: 1 of selection_*
falsepositives:
    - Unlikely legitimate usage of AutoIT in temp folders.
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.