General

  • Target

    1df0c7c729ccdc49e0fc71819412132a_JaffaCakes118

  • Size

    481KB

  • Sample

    240702-em9ywsydrm

  • MD5

    1df0c7c729ccdc49e0fc71819412132a

  • SHA1

    ecebd81250c6b16e35d3924a4c39f3c3dd453f90

  • SHA256

    a1de09c8da8de9a7c9c82714862048aadcc3871092215a974ad5fbad3abca818

  • SHA512

    6c568d367881071bfba3cc9139358283e0c172c36574cb7c6106b45865b447f6fa023cf88f1a47356f2c3b01c12c0c8fa67c982515c569664cd386f1dcba0de5

  • SSDEEP

    12288:avqCFCIMdZwuPTkKfVyBltKPsxBVr0Qho:QTCHFkKfcvKPs5oQho

Malware Config

Extracted

Family

darkcomet

Botnet

Guest16

C2

127.0.0.1:1604

Mutex

DC_MUTEX-4HXZTX0

Attributes
  • gencode

    k01PruSfoVRz

  • install

    false

  • offline_keylogger

    true

  • persistence

    false

Targets

    • Target

      1df0c7c729ccdc49e0fc71819412132a_JaffaCakes118

    • Size

      481KB

    • MD5

      1df0c7c729ccdc49e0fc71819412132a

    • SHA1

      ecebd81250c6b16e35d3924a4c39f3c3dd453f90

    • SHA256

      a1de09c8da8de9a7c9c82714862048aadcc3871092215a974ad5fbad3abca818

    • SHA512

      6c568d367881071bfba3cc9139358283e0c172c36574cb7c6106b45865b447f6fa023cf88f1a47356f2c3b01c12c0c8fa67c982515c569664cd386f1dcba0de5

    • SSDEEP

      12288:avqCFCIMdZwuPTkKfVyBltKPsxBVr0Qho:QTCHFkKfcvKPs5oQho

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks