MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13429271d76c4c33d286cc91d897a1e81c7c442ba6523b56685562e73cb19e60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 13429271d76c4c33d286cc91d897a1e81c7c442ba6523b56685562e73cb19e60
SHA3-384 hash: 5f07bbcb6a94ab0c2fa36f6a16e1cd3d25d226cc7c0bbc7d1be264d0dd31db7bbe8b770b5e3595dcb4a83e0fa7abbaf9
SHA1 hash: 688dcb8b9f2c86b34f24a15fba1ab63a1f92bdde
MD5 hash: b5996cdb94e764901c8794d3f2a6c4f5
humanhash: lamp-avocado-music-snake
File name:13429271d76c4c33d286cc91d897a1e81c7c442ba6523b56685562e73cb19e60
Download: download sample
File size:258'048 bytes
First seen:2020-06-10 11:35:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a38ad86d74cafc45094a5085e33419e4 (108 x DarkComet, 1 x njrat)
ssdeep 6144:ZcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PHQ:ZcWkbgTYWnYnt/IDYhP
Threatray 67 similar samples on MalwareBazaar
TLSH 9E442306FA950A09F2F8FC7F27C653A6858C567BFFBD0052BB51670EB06A616031D34A
Reporter JAMESWT_WT

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Backdoor.DarkComet
Status:
Malicious
First seen:
2020-06-05 23:03:57 UTC
File Type:
PE (Exe)
Extracted files:
24
AV detection:
29 of 29 (100.00%)
Threat level:
  5/5
Result
Malware family:
darkcomet
Score:
  10/10
Tags:
family:darkcomet evasion persistence rat trojan upx
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Views/modifies file attributes
Modifies registry class
Modifies service
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Deletes itself
Loads dropped DLL
Windows security modification
Disables RegEdit via registry modification
Executes dropped EXE
Sets file to hidden
UPX packed file
Darkcomet
Modifies WinLogon for persistence
Modifies firewall policy service
Modifies security service
Windows security bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments