General

  • Target

    1873821ac1b379bbee9bf8a28a3df25b_JaffaCakes118

  • Size

    440KB

  • Sample

    240628-cwes1awemg

  • MD5

    1873821ac1b379bbee9bf8a28a3df25b

  • SHA1

    e58fb40df6785cf84802b8b6801b8753a7a9f6d5

  • SHA256

    d87cde75993382d263bf658a0935a6bdd0bec09b6941d6c8bc5d729f5ae4a2c1

  • SHA512

    8a06b1f3efe8b38e9facf4fb7dc39560b5c485beda499025414215e21ac57ba0e983f7f21cab49dac0c9bc506591f76a987a691cde46f45cb455320c2d694e57

  • SSDEEP

    12288:+HXWBsS/FFY7VGWolpGrki9CAO/QFW5lXM:+G6MF4RoPGrLC3fXM

Score
10/10

Malware Config

Targets

    • Target

      1873821ac1b379bbee9bf8a28a3df25b_JaffaCakes118

    • Size

      440KB

    • MD5

      1873821ac1b379bbee9bf8a28a3df25b

    • SHA1

      e58fb40df6785cf84802b8b6801b8753a7a9f6d5

    • SHA256

      d87cde75993382d263bf658a0935a6bdd0bec09b6941d6c8bc5d729f5ae4a2c1

    • SHA512

      8a06b1f3efe8b38e9facf4fb7dc39560b5c485beda499025414215e21ac57ba0e983f7f21cab49dac0c9bc506591f76a987a691cde46f45cb455320c2d694e57

    • SSDEEP

      12288:+HXWBsS/FFY7VGWolpGrki9CAO/QFW5lXM:+G6MF4RoPGrLC3fXM

    Score
    10/10
    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

3
T1012

System Information Discovery

3
T1082

Tasks