General

  • Target

    1826a3c3cbaf8804560951543a1cf444_JaffaCakes118

  • Size

    646KB

  • Sample

    240628-az46ystfll

  • MD5

    1826a3c3cbaf8804560951543a1cf444

  • SHA1

    54d252204e522b347e7ae12fde66ee6049c3d18a

  • SHA256

    77d996c69a16c1be2b9ce2c80f10b89c3177dcdedde4f807898049c9af1fe372

  • SHA512

    c79e510da682cee76a4d3f4509da73314a5752dc34b724de7da5aeb94208ccd3e29940f0989d34eddb28bcc4bfad771d9fca15f94eb496e736314faeae9b5491

  • SSDEEP

    12288:g8UaT9XY2siA0bMG09xD7I3Gg8ecgVvfBoCDBOQQYbVXpuy1f/gORix2:ZUKoN0bUxgGa/pfBHDb+y1HgZA

Malware Config

Targets

    • Target

      1826a3c3cbaf8804560951543a1cf444_JaffaCakes118

    • Size

      646KB

    • MD5

      1826a3c3cbaf8804560951543a1cf444

    • SHA1

      54d252204e522b347e7ae12fde66ee6049c3d18a

    • SHA256

      77d996c69a16c1be2b9ce2c80f10b89c3177dcdedde4f807898049c9af1fe372

    • SHA512

      c79e510da682cee76a4d3f4509da73314a5752dc34b724de7da5aeb94208ccd3e29940f0989d34eddb28bcc4bfad771d9fca15f94eb496e736314faeae9b5491

    • SSDEEP

      12288:g8UaT9XY2siA0bMG09xD7I3Gg8ecgVvfBoCDBOQQYbVXpuy1f/gORix2:ZUKoN0bUxgGa/pfBHDb+y1HgZA

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Modifies WinLogon for persistence

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks