General

  • Target

    1d7a2029aebcbfdb57989b1705e7f0fe_JaffaCakes118

  • Size

    649KB

  • Sample

    240702-z5xrhazdmc

  • MD5

    1d7a2029aebcbfdb57989b1705e7f0fe

  • SHA1

    88826689aad7d515d82542e838feb92eb7ade847

  • SHA256

    4a758df2a8ca97f6fc2acdc22e68d3149a64ecabdb070aef1fe5805d5f983bde

  • SHA512

    b45fe24b4a0d17f58c0bcff498cb8c6206f27a03138ebe49085f3712e1227455727d9310c2e8374f138fb69464f85bc5285335ee6f947fc50577efd6f84b9fc2

  • SSDEEP

    12288:bk0QVlhmPojAPTMEsUTg0oChO/Q2JbsbjPbN5qhRTtYe3f+Iw86k/9/+d:Q0QRWoJEfg0oChGdJQbjPbNW5tYeP+GU

Malware Config

Extracted

Family

darkcomet

Botnet

First

C2

th3v3rdict.no-ip.org:1732

Mutex

DC_MUTEX-4ZC6MJK

Attributes
  • gencode

    sqBwzcsC15mD

  • install

    false

  • offline_keylogger

    true

  • password

    uytr13

  • persistence

    false

Targets

    • Target

      1d7a2029aebcbfdb57989b1705e7f0fe_JaffaCakes118

    • Size

      649KB

    • MD5

      1d7a2029aebcbfdb57989b1705e7f0fe

    • SHA1

      88826689aad7d515d82542e838feb92eb7ade847

    • SHA256

      4a758df2a8ca97f6fc2acdc22e68d3149a64ecabdb070aef1fe5805d5f983bde

    • SHA512

      b45fe24b4a0d17f58c0bcff498cb8c6206f27a03138ebe49085f3712e1227455727d9310c2e8374f138fb69464f85bc5285335ee6f947fc50577efd6f84b9fc2

    • SSDEEP

      12288:bk0QVlhmPojAPTMEsUTg0oChO/Q2JbsbjPbN5qhRTtYe3f+Iw86k/9/+d:Q0QRWoJEfg0oChGdJQbjPbNW5tYeP+GU

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

MITRE ATT&CK Matrix ATT&CK v13

Tasks