General

  • Target

    15e79e75f052a82d3e1a2cd88028596f_JaffaCakes118

  • Size

    1.3MB

  • Sample

    240627-n1xp6azdna

  • MD5

    15e79e75f052a82d3e1a2cd88028596f

  • SHA1

    ec3f2e8e2fe31d232bd45d7d54c79dbe81c47994

  • SHA256

    938bfda0209c6bb2e28e0094245a0ce708c75f19b42a557054d9a1efde1b1335

  • SHA512

    8b425d73fb21de18b8fa549a2719cc22da45e0eccd45c1168ee2ffdfd26dd1db3090a0ebd1eb28608e7dad6d1f60de54246f232579c134e779d4a9114ff16ab3

  • SSDEEP

    24576:1BjwYUcORkNuE9agxxs3HAfpnJ+xxxgQUSFKJnNiu/J5tL:qcuE9xxs3HAB8xTflFKJNx/VL

Malware Config

Targets

    • Target

      15e79e75f052a82d3e1a2cd88028596f_JaffaCakes118

    • Size

      1.3MB

    • MD5

      15e79e75f052a82d3e1a2cd88028596f

    • SHA1

      ec3f2e8e2fe31d232bd45d7d54c79dbe81c47994

    • SHA256

      938bfda0209c6bb2e28e0094245a0ce708c75f19b42a557054d9a1efde1b1335

    • SHA512

      8b425d73fb21de18b8fa549a2719cc22da45e0eccd45c1168ee2ffdfd26dd1db3090a0ebd1eb28608e7dad6d1f60de54246f232579c134e779d4a9114ff16ab3

    • SSDEEP

      24576:1BjwYUcORkNuE9agxxs3HAfpnJ+xxxgQUSFKJnNiu/J5tL:qcuE9xxs3HAB8xTflFKJNx/VL

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Modifies WinLogon for persistence

    • Sets file to hidden

      Modifies file attributes to stop it showing in Explorer etc.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Hide Artifacts

2
T1564

Hidden Files and Directories

2
T1564.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks