General

  • Target

    0499a29090ec8925c8a0e9e72f4e0016_JaffaCakes118

  • Size

    838KB

  • Sample

    240623-ay6y6ascna

  • MD5

    0499a29090ec8925c8a0e9e72f4e0016

  • SHA1

    2620812b949fc579d29a356022915ae5fab467d7

  • SHA256

    26a1fe63dcd694f139823a900d33743b9af9bcf65af92cf73b8cc0e3eaba4494

  • SHA512

    4f5e6cb89149e26a8041f72da446e138bf593f8325da3fc85afc20d6189e6a440ad330170d603ca1c61f766da95caff6fccc65917fedd27bd1165a835c6b8315

  • SSDEEP

    12288:HeesEQ5idun7RE529VLgoSf9dyFVuIQ/jLNp1c9Kj1:Hp8idO1EG/zuRzj1

Malware Config

Extracted

Family

darkcomet

Botnet

Guest16

C2

127.0.0.1:999

Mutex

DC_MUTEX-J85WU8X

Attributes
  • gencode

    PmeTdyUBGq5o

  • install

    false

  • offline_keylogger

    false

  • password

    73810052

  • persistence

    false

Targets

    • Target

      0499a29090ec8925c8a0e9e72f4e0016_JaffaCakes118

    • Size

      838KB

    • MD5

      0499a29090ec8925c8a0e9e72f4e0016

    • SHA1

      2620812b949fc579d29a356022915ae5fab467d7

    • SHA256

      26a1fe63dcd694f139823a900d33743b9af9bcf65af92cf73b8cc0e3eaba4494

    • SHA512

      4f5e6cb89149e26a8041f72da446e138bf593f8325da3fc85afc20d6189e6a440ad330170d603ca1c61f766da95caff6fccc65917fedd27bd1165a835c6b8315

    • SSDEEP

      12288:HeesEQ5idun7RE529VLgoSf9dyFVuIQ/jLNp1c9Kj1:Hp8idO1EG/zuRzj1

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks