General

  • Target

    0845de55c35f500267ce237f7e0e0646_JaffaCakes118

  • Size

    450KB

  • Sample

    240624-nptt5atcnm

  • MD5

    0845de55c35f500267ce237f7e0e0646

  • SHA1

    d1502533a3a569e63635109ec573af692660cf6e

  • SHA256

    20b34052f05c6ead3b3888d418f81df05df369e1e7a4cc3ef52b32b7dbf5535d

  • SHA512

    c260c16f031be4a540c7e97534a5f7fc4ee09d09fed2494a990b1d34b6a9638f5f148132042a5ff7b6423973d2799a12997e2c9ab3477e4489b49ab735c7740c

  • SSDEEP

    6144:qSsPBTX9n8VunKEVAwTt91Kkb8qBoGU5tex3598gWNlPTGQQm6agrdu555:qSCJn8EAe9DhO/GYNtTirdu

Malware Config

Extracted

Family

darkcomet

Botnet

Guest16

C2

saw-88.no-ip.biz:1604

Mutex

DC_MUTEX-2GB2XT7

Attributes
  • InstallPath

    MSDCSC\msdcsc.exe

  • gencode

    Hbi4xuTnnr1N

  • install

    true

  • offline_keylogger

    true

  • persistence

    true

  • reg_key

    MicroUpdate

Targets

    • Target

      0845de55c35f500267ce237f7e0e0646_JaffaCakes118

    • Size

      450KB

    • MD5

      0845de55c35f500267ce237f7e0e0646

    • SHA1

      d1502533a3a569e63635109ec573af692660cf6e

    • SHA256

      20b34052f05c6ead3b3888d418f81df05df369e1e7a4cc3ef52b32b7dbf5535d

    • SHA512

      c260c16f031be4a540c7e97534a5f7fc4ee09d09fed2494a990b1d34b6a9638f5f148132042a5ff7b6423973d2799a12997e2c9ab3477e4489b49ab735c7740c

    • SSDEEP

      6144:qSsPBTX9n8VunKEVAwTt91Kkb8qBoGU5tex3598gWNlPTGQQm6agrdu555:qSCJn8EAe9DhO/GYNtTirdu

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

MITRE ATT&CK Matrix

Tasks