General

  • Target

    1c2d1c88e9597535bc77f312f3eed94b_JaffaCakes118

  • Size

    758KB

  • MD5

    1c2d1c88e9597535bc77f312f3eed94b

  • SHA1

    5313e64a644abf63c7a653ef3383d2cba4bb2470

  • SHA256

    151a6374669a557f4b91682dff916e16088173c995f4cbf239b6d8828886ec89

  • SHA512

    b435a3f06d218ce817783c5e3783e210bdc3860d7e330b4953a1b7b2a08e0c925b8937f52d6c6947c32613aceec1bc31897289a4c2bea81e2b12e563a8195ab4

  • SSDEEP

    12288:8X2JVHMRtDaSm3TJvVNvWV5YTsY7tHwbz/htfcoCoK632zb7G/QoFCk:qss2Sm39NNv9wY7tHwbzfIoK6Mook

Score
10/10

Malware Config

Extracted

Family

darkcomet

Botnet

nsm

C2

dark.dnsd.info:1604

Mutex

DC_MUTEX-BBCMREG

Attributes
  • InstallPath

    MSDCSC\lsassc.exe

  • gencode

    rArbm2GK8iZn

  • install

    true

  • offline_keylogger

    false

  • persistence

    true

  • reg_key

    lsass.exe

Signatures

  • Darkcomet family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 1c2d1c88e9597535bc77f312f3eed94b_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    6f0fecaae0f40ed3ea31df971b69bcca


    Headers

    Imports

    Sections