General

  • Target

    15ce45fdf58db94c01d9379c4f0148f2_JaffaCakes118

  • Size

    616KB

  • Sample

    240627-nfhqhaycmf

  • MD5

    15ce45fdf58db94c01d9379c4f0148f2

  • SHA1

    74aa27d81f3a3d1cf544f6b2c6e8ea160654fac0

  • SHA256

    8439f3656b12b448b15f43c7ea8a8871ea978aaa3f3140af622682d0ac06b8ce

  • SHA512

    651fe20068e868a418cb64af078470be30017fa71d25bca9a1781511f2b135bc71a7ab4a71e7401e11fc20f536b8aecb982ff131f390ca0c135ac2f9336f346f

  • SSDEEP

    12288:YePwlp7/N0+OLbetJZv5m0/VyVz9ZPYHm1GjD2JSmJVRC:fmS+OEZvMQAFAmMeJSmfw

Malware Config

Targets

    • Target

      15ce45fdf58db94c01d9379c4f0148f2_JaffaCakes118

    • Size

      616KB

    • MD5

      15ce45fdf58db94c01d9379c4f0148f2

    • SHA1

      74aa27d81f3a3d1cf544f6b2c6e8ea160654fac0

    • SHA256

      8439f3656b12b448b15f43c7ea8a8871ea978aaa3f3140af622682d0ac06b8ce

    • SHA512

      651fe20068e868a418cb64af078470be30017fa71d25bca9a1781511f2b135bc71a7ab4a71e7401e11fc20f536b8aecb982ff131f390ca0c135ac2f9336f346f

    • SSDEEP

      12288:YePwlp7/N0+OLbetJZv5m0/VyVz9ZPYHm1GjD2JSmJVRC:fmS+OEZvMQAFAmMeJSmfw

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Modifies firewall policy service

    • Disables Task Manager via registry modification

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

1
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Discovery

Query Registry

3
T1012

System Information Discovery

4
T1082

Tasks