General

  • Target

    1b13307e9a80276dc3308fbd36149516_JaffaCakes118

  • Size

    658KB

  • Sample

    240701-nav4msybjb

  • MD5

    1b13307e9a80276dc3308fbd36149516

  • SHA1

    7ef826accaa85f4b4ac9e77a9e1460abd6d275c9

  • SHA256

    486ad036a88e5035cf96c530fb7434aa27dee9ff54a213d1cc2853eed0000fb9

  • SHA512

    fdcbe39d216640d9b96d7b749d975536de67fb8d3fcc5d3fc383ecfcb9f0da3e02b04e1ce322b54783a1d855e83e76fd39b2e59d78144642bee902e24095ec01

  • SSDEEP

    12288:R9AFlAd0Z+89cxTGzO4AucTD8QP2lmFSrVs9LqnK2g:nAQ6Zx9cxTmOrucTIEFSpOG7g

Score
10/10

Malware Config

Targets

    • Target

      1b13307e9a80276dc3308fbd36149516_JaffaCakes118

    • Size

      658KB

    • MD5

      1b13307e9a80276dc3308fbd36149516

    • SHA1

      7ef826accaa85f4b4ac9e77a9e1460abd6d275c9

    • SHA256

      486ad036a88e5035cf96c530fb7434aa27dee9ff54a213d1cc2853eed0000fb9

    • SHA512

      fdcbe39d216640d9b96d7b749d975536de67fb8d3fcc5d3fc383ecfcb9f0da3e02b04e1ce322b54783a1d855e83e76fd39b2e59d78144642bee902e24095ec01

    • SSDEEP

      12288:R9AFlAd0Z+89cxTGzO4AucTD8QP2lmFSrVs9LqnK2g:nAQ6Zx9cxTmOrucTIEFSpOG7g

    Score
    10/10
    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

3
T1012

System Information Discovery

3
T1082

Tasks