General

  • Target

    19ae0c3eba9091ca7daea2db9b5f3f09_JaffaCakes118

  • Size

    649KB

  • Sample

    240628-lskphswarp

  • MD5

    19ae0c3eba9091ca7daea2db9b5f3f09

  • SHA1

    1e9cf220cccc2155aa0d41ae401d584ebb98863a

  • SHA256

    2fa1ab454114dc94dd69ae6e2f2a31270bd7f00e8ea454317791374a767a3cdf

  • SHA512

    dd471891a6e439f9babe91dcd10ce60e9d1a9b2857544224fcd94c96d02c72c5c1a1909497c6f7c060f7021405e66b0ecc1395134f604127d9c1d4692db187d5

  • SSDEEP

    12288:bk0QVlhmPojAPTMEsUTg0oChO/Q2JbsbjPbN5qhRTtYe3f+Iw86k/9/+A:Q0QRWoJEfg0oChGdJQbjPbNW5tYeP+G9

Malware Config

Extracted

Family

darkcomet

Botnet

Habbo Gen

C2

82.41.38.18:1995

Mutex

DC_MUTEX-5WTNQ5D

Attributes
  • gencode

    Qn34A2Y5nQa0

  • install

    false

  • offline_keylogger

    true

  • persistence

    false

Targets

    • Target

      19ae0c3eba9091ca7daea2db9b5f3f09_JaffaCakes118

    • Size

      649KB

    • MD5

      19ae0c3eba9091ca7daea2db9b5f3f09

    • SHA1

      1e9cf220cccc2155aa0d41ae401d584ebb98863a

    • SHA256

      2fa1ab454114dc94dd69ae6e2f2a31270bd7f00e8ea454317791374a767a3cdf

    • SHA512

      dd471891a6e439f9babe91dcd10ce60e9d1a9b2857544224fcd94c96d02c72c5c1a1909497c6f7c060f7021405e66b0ecc1395134f604127d9c1d4692db187d5

    • SSDEEP

      12288:bk0QVlhmPojAPTMEsUTg0oChO/Q2JbsbjPbN5qhRTtYe3f+Iw86k/9/+A:Q0QRWoJEfg0oChGdJQbjPbNW5tYeP+G9

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Modifies firewall policy service

    • Modifies security service

    • Windows security bypass

    • Disables RegEdit via registry modification

    • Disables Task Manager via registry modification

    • Sets file to hidden

      Modifies file attributes to stop it showing in Explorer etc.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Windows security modification

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Privilege Escalation

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Defense Evasion

Modify Registry

5
T1112

Impair Defenses

3
T1562

Disable or Modify Tools

2
T1562.001

Disable or Modify System Firewall

1
T1562.004

Hide Artifacts

2
T1564

Hidden Files and Directories

2
T1564.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks