General

  • Target

    24c1e5d419b0eecccc15a74b7c56edeb_JaffaCakes118

  • Size

    650KB

  • MD5

    24c1e5d419b0eecccc15a74b7c56edeb

  • SHA1

    d67d5dea6e2d3bba041a59b9b60c877ac25931c0

  • SHA256

    8974b93e1437e29d027c8e69c22b4d95b81fa541db02a9848d73a3ae3c231511

  • SHA512

    e72e93f3d5910a231fb4c6b1cf4e6a5b11e929cca76fdf15a4df890c569d59314a64d3ab5bb4f5be004331a870ef303a099c045d94db5e68b1794b613db12986

  • SSDEEP

    12288:Lk0QVlhmPojAPTMEsUTg0oChO/Q2JbsbjPbN5qhRTtYe3f+Iw86k/9/+c:g0QRWoJEfg0oChGdJQbjPbNW5tYeP+GJ

Score
10/10

Malware Config

Extracted

Family

darkcomet

Botnet

JAVAappDrBy1

C2

epiclegit.no-ip.biz:1337

Mutex

DC_MUTEX-V0B2QA6

Attributes
  • InstallPath

    Java\JavawsJRE06.exe

  • gencode

    kCoeYQ87hhHK

  • install

    true

  • offline_keylogger

    true

  • persistence

    true

  • reg_key

    JavaUpdater

Signatures

  • Darkcomet family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 24c1e5d419b0eecccc15a74b7c56edeb_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    d9ad5efdb5472496d0fe8dd4305f55f0


    Headers

    Imports

    Sections