General

  • Target

    171bef4ec12a568a8496e2c39e5f4e8e_JaffaCakes118

  • Size

    927KB

  • Sample

    240627-xen1kavdlc

  • MD5

    171bef4ec12a568a8496e2c39e5f4e8e

  • SHA1

    d019dd3f9004920f13b20e5d95586d7a384ebb0b

  • SHA256

    85112b77cbc006585648662b56b53fa526093e2689398078ff7ee14d0929bf01

  • SHA512

    e58a473c16c973f5f29bddfb93dbdc36440e63869ecd7af32f0761f2e38e73088b54e5f88d6183ab34606b5a0e6444b5f479c5e9f0f5092c525b824f411bc847

  • SSDEEP

    24576:wFC/G4K2wSSSMjwvgFS5bJ5TMhmvviZ46hq+:wFR4/lgiKaIq

Malware Config

Targets

    • Target

      171bef4ec12a568a8496e2c39e5f4e8e_JaffaCakes118

    • Size

      927KB

    • MD5

      171bef4ec12a568a8496e2c39e5f4e8e

    • SHA1

      d019dd3f9004920f13b20e5d95586d7a384ebb0b

    • SHA256

      85112b77cbc006585648662b56b53fa526093e2689398078ff7ee14d0929bf01

    • SHA512

      e58a473c16c973f5f29bddfb93dbdc36440e63869ecd7af32f0761f2e38e73088b54e5f88d6183ab34606b5a0e6444b5f479c5e9f0f5092c525b824f411bc847

    • SSDEEP

      24576:wFC/G4K2wSSSMjwvgFS5bJ5TMhmvviZ46hq+:wFR4/lgiKaIq

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Uses the VBS compiler for execution

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scripting

1
T1064

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Scripting

1
T1064

Modify Registry

1
T1112

Tasks