General

  • Target

    174f6ff5bdb4c4bbd35534e61147866f_JaffaCakes118

  • Size

    1.0MB

  • Sample

    240627-ykvwqszdpj

  • MD5

    174f6ff5bdb4c4bbd35534e61147866f

  • SHA1

    0d191afc84cd1cedf74fe6b7eefedafeabf6fa9c

  • SHA256

    3a067942f8e86aa1267b8bad398dc683aa189082cc86964ac93116f4fca089e1

  • SHA512

    a062ef8d98ea052c1e0019d50980211770ff76e74f6a8ac3903236c254bdd1f604bd9f824812bd08275c112c4ca0b4cb2b8996704e3177ceb3d8112e057af345

  • SSDEEP

    24576:09yzZQBIrvzTevzSCvS/Lq+uGGGCCUAx2l:09CQarvznCvS/LkGXCPAO

Score
10/10

Malware Config

Targets

    • Target

      174f6ff5bdb4c4bbd35534e61147866f_JaffaCakes118

    • Size

      1.0MB

    • MD5

      174f6ff5bdb4c4bbd35534e61147866f

    • SHA1

      0d191afc84cd1cedf74fe6b7eefedafeabf6fa9c

    • SHA256

      3a067942f8e86aa1267b8bad398dc683aa189082cc86964ac93116f4fca089e1

    • SHA512

      a062ef8d98ea052c1e0019d50980211770ff76e74f6a8ac3903236c254bdd1f604bd9f824812bd08275c112c4ca0b4cb2b8996704e3177ceb3d8112e057af345

    • SSDEEP

      24576:09yzZQBIrvzTevzSCvS/Lq+uGGGCCUAx2l:09CQarvznCvS/LkGXCPAO

    Score
    10/10
    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Executes dropped EXE

    • Loads dropped DLL

    • Uses the VBS compiler for execution

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scripting

1
T1064

Defense Evasion

Scripting

1
T1064

Tasks