General

  • Target

    1753e5c51e39ae8b979d2b7ce213a446_JaffaCakes118

  • Size

    804KB

  • Sample

    240627-ypeejszflm

  • MD5

    1753e5c51e39ae8b979d2b7ce213a446

  • SHA1

    52e63b19aee9ba61c753593b0089cc6e352bf5cc

  • SHA256

    c3bab0f648527f6f1ce39bd437ca304d57264c4d45dd2bddef79f39be956640e

  • SHA512

    879ec0e1b861b574062d20d5aa9be06020870103c86c932a014826882c9ba48443142cc660630fd8da467c8470a6cf4d59d70e6fb2c6767898a5199c328368d0

  • SSDEEP

    12288:bK1q+iF0S+Xi+FSiSFVpIfi7CQc8FTnE97SFdmFnItdDlM2j:bICmS+XNF3aEsCQc8CSDo0dj

Malware Config

Targets

    • Target

      1753e5c51e39ae8b979d2b7ce213a446_JaffaCakes118

    • Size

      804KB

    • MD5

      1753e5c51e39ae8b979d2b7ce213a446

    • SHA1

      52e63b19aee9ba61c753593b0089cc6e352bf5cc

    • SHA256

      c3bab0f648527f6f1ce39bd437ca304d57264c4d45dd2bddef79f39be956640e

    • SHA512

      879ec0e1b861b574062d20d5aa9be06020870103c86c932a014826882c9ba48443142cc660630fd8da467c8470a6cf4d59d70e6fb2c6767898a5199c328368d0

    • SSDEEP

      12288:bK1q+iF0S+Xi+FSiSFVpIfi7CQc8FTnE97SFdmFnItdDlM2j:bICmS+XNF3aEsCQc8CSDo0dj

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Modifies WinLogon for persistence

    • Executes dropped EXE

    • Uses the VBS compiler for execution

    • Adds Run key to start application

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scripting

1
T1064

Persistence

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Scripting

1
T1064

Discovery

Remote System Discovery

1
T1018

Tasks