MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DarkComet


Vendor detections: 16


Intelligence 16 IOCs YARA 7 File information Comments

SHA256 hash: 9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b
SHA3-384 hash: 96e001469cf7a24df71e0ca5c471bee6258a96bb6323120a54b74fc09bbf91501a4090761115c8f83ab380ec90c1d90d
SHA1 hash: 237a64bbd29b1ef2ab180b57f3ad0b3a8fc9328c
MD5 hash: 7f7068a82f43b3e5769e26fab1faa7da
humanhash: idaho-network-summer-mexico
File name:PO#4590OQ.bat
Download: download sample
Signature DarkComet
File size:1'404'424 bytes
First seen:2025-02-03 08:40:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'650 x AgentTesla, 19'462 x Formbook, 12'203 x SnakeKeylogger)
ssdeep 24576:5we0qDl5kbFWwASTXbsAAD4XNMEZZKO1p5UYeiysUJGcj23a2tjXQHwtk:5wNqDl5koRSPJAeOESO1bUYeiysUAcj/
Threatray 13 similar samples on MalwareBazaar
TLSH T1355502D43B6AA706DDA55930D939EDB4927D2DAC7100F8E71EDD3B4BB8982106E0CF06
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
File icon (PE):PE icon
dhash icon e0e698a08088a888 (20 x Formbook, 6 x AgentTesla, 3 x SnakeKeylogger)
Reporter threatcat_ch
Tags:DarkComet exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
515
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
PO#4590OQ.bat
Verdict:
Malicious activity
Analysis date:
2025-02-03 08:41:07 UTC
Tags:
xred backdoor evasion snake keylogger stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
kryptik micro msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
invalid-signature masquerade obfuscated packed packed packer_detected phishing signed vbnet
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
MassLogger RAT, XRed
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
AI detected suspicious PE digital signature
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Contains functionality to log keystrokes (.Net Source)
Drops PE files to the document folder of the user
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Sigma detected: Suspicious Executable File Creation
Suricata IDS alerts for network traffic
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Yara detected MassLogger RAT
Yara detected Telegram RAT
Yara detected XRed
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1605410 Sample: PO#4590OQ.bat.exe Startdate: 03/02/2025 Architecture: WINDOWS Score: 100 110 reallyfreegeoip.org 2->110 112 freedns.afraid.org 2->112 114 7 other IPs or domains 2->114 128 Suricata IDS alerts for network traffic 2->128 130 Found malware configuration 2->130 132 Malicious sample detected (through community Yara rule) 2->132 138 19 other signatures 2->138 10 PO#4590OQ.bat.exe 7 2->10         started        14 KLToLsNsEmafCb.exe 2->14         started        16 Synaptics.exe 2->16         started        18 EXCEL.EXE 2->18         started        signatures3 134 Tries to detect the country of the analysis system (by using the IP) 110->134 136 Uses dynamic DNS services 112->136 process4 file5 94 C:\Users\user\AppData\...\KLToLsNsEmafCb.exe, PE32 10->94 dropped 96 C:\...\KLToLsNsEmafCb.exe:Zone.Identifier, ASCII 10->96 dropped 98 C:\Users\user\AppData\Local\...\tmpCCA4.tmp, XML 10->98 dropped 100 C:\Users\user\...\PO#4590OQ.bat.exe.log, ASCII 10->100 dropped 160 Uses schtasks.exe or at.exe to add and modify task schedules 10->160 162 Adds a directory exclusion to Windows Defender 10->162 164 Injects a PE file into a foreign processes 10->164 166 Contains functionality to detect sleep reduction / modifications 10->166 20 PO#4590OQ.bat.exe 1 5 10->20         started        23 powershell.exe 23 10->23         started        26 powershell.exe 23 10->26         started        28 schtasks.exe 1 10->28         started        168 Multi AV Scanner detection for dropped file 14->168 170 Machine Learning detection for dropped file 14->170 30 KLToLsNsEmafCb.exe 14->30         started        32 schtasks.exe 14->32         started        34 Synaptics.exe 16->34         started        38 2 other processes 16->38 36 splwow64.exe 18->36         started        signatures6 process7 file8 84 C:\Users\user\...\._cache_PO#4590OQ.bat.exe, PE32 20->84 dropped 86 C:\ProgramData\Synaptics\Synaptics.exe, PE32 20->86 dropped 88 C:\...\Synaptics.exe:Zone.Identifier, ASCII 20->88 dropped 40 Synaptics.exe 20->40         started        43 ._cache_PO#4590OQ.bat.exe 15 2 20->43         started        140 Loading BitLocker PowerShell Module 23->140 46 conhost.exe 23->46         started        48 conhost.exe 26->48         started        50 conhost.exe 28->50         started        90 C:\Users\user\...\._cache_KLToLsNsEmafCb.exe, PE32 30->90 dropped 52 ._cache_KLToLsNsEmafCb.exe 30->52         started        54 conhost.exe 32->54         started        92 C:\ProgramData\...\._cache_Synaptics.exe, PE32 34->92 dropped 56 ._cache_Synaptics.exe 34->56         started        58 conhost.exe 38->58         started        signatures9 process10 dnsIp11 146 Multi AV Scanner detection for dropped file 40->146 148 Drops PE files to the document folder of the user 40->148 150 Machine Learning detection for dropped file 40->150 158 2 other signatures 40->158 60 Synaptics.exe 40->60         started        64 powershell.exe 40->64         started        67 powershell.exe 40->67         started        69 2 other processes 40->69 116 checkip.dyndns.com 132.226.8.169, 49709, 49713, 49737 UTMEMUS United States 43->116 118 reallyfreegeoip.org 104.21.48.1, 443, 49712, 49714 CLOUDFLARENETUS United States 43->118 152 Antivirus detection for dropped file 52->152 154 Tries to steal Mail credentials (via file / registry access) 52->154 156 Tries to harvest and steal browser information (history, passwords, etc) 52->156 signatures12 process13 dnsIp14 120 drive.usercontent.google.com 142.250.185.225, 443, 49732, 49733 GOOGLEUS United States 60->120 122 docs.google.com 216.58.206.46, 443, 49721, 49722 GOOGLEUS United States 60->122 124 freedns.afraid.org 69.42.215.252, 49730, 80 AWKNET-LLCUS United States 60->124 102 C:\Users\user\Documents\BJZFPPWAPT\~$cache1, PE32 60->102 dropped 104 C:\Users\user\Desktop\._cache_Synaptics.exe, PE32 60->104 dropped 106 C:\Users\user\AppData\Local\...\nC6TallF.exe, PE32 60->106 dropped 108 3 other malicious files 60->108 dropped 71 ._cache_Synaptics.exe 60->71         started        74 WerFault.exe 60->74         started        76 WerFault.exe 60->76         started        126 Loading BitLocker PowerShell Module 64->126 78 conhost.exe 64->78         started        80 conhost.exe 67->80         started        82 conhost.exe 69->82         started        file15 signatures16 process17 signatures18 142 Multi AV Scanner detection for dropped file 71->142 144 Tries to steal Mail credentials (via file / registry access) 71->144
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2025-02-03 05:11:45 UTC
File Type:
PE (.Net Exe)
Extracted files:
6
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xred backdoor collection discovery execution persistence spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Xred
Xred family
Malware Config
C2 Extraction:
xred.mooo.com
Unpacked files
SH256 hash:
9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b
MD5 hash:
7f7068a82f43b3e5769e26fab1faa7da
SHA1 hash:
237a64bbd29b1ef2ab180b57f3ad0b3a8fc9328c
SH256 hash:
9dc80d1a0857740b4b18a6758de8b98517e025bf812df9fb34da394e0d262a00
MD5 hash:
9ce27440835c21f5b5ddc75b83d5367d
SHA1 hash:
32d465645b85d80f918f407826c38d964f8c9248
SH256 hash:
b6fe518ed8ca7ee32f79bb5dd52ab8250cc595d1aa8daec123cef383c6b0bdb6
MD5 hash:
b45e3c4c10da3da0c69e2f90dc3dfb10
SHA1 hash:
61a36473ced38978793a9af1aea1fc528eebe457
Detections:
MAL_Envrial_Jan18_1 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
Parent samples :
2e60e1e443fe9ccbc167bd093cbea48ed49743648f5c8df81c9d7356ac499194
b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485
3bbeda749854caa304bb1e8b968971a7e84359f98105c9ef80d18033adcc2f09
ad2f3629f617763f45abc1be39c4a28f581ca8d0efb97e3bde2ad33106714c85
0004912ccca96809295d0383d2febcd100a386ed262d9912f1a02e886ae460c0
195ee9a9f96abb146c2c217c659c7cd66093d607b9a64a1ffe976a32eee81b2c
4e007a23a0658f7417c1767bf2f2a0a3722853216e9a00489f79d57b555acc9e
f68c0c40aa651d080967ea4ea3c389fc1e3dbafcd097ac10f01374d0f6ae52d3
862a367b1e130dc47d08a2d4ce26bec8d85196f00c1a3f6c0df4fc5f099139cd
29ce0132efcb5e1aad146065672d83b6b4ced076f1c91a851c8b34a30e7e08eb
45def37a33ac8c66332d64929636aa908916c5a4c4b17ff5724de5564d066105
593995d24730f261cde9c772b7fddbbc57b02d36418905ba7a95b78609d4a258
8835d6d5566c121cb4fd76ef710de856b803636037b510524d3de684071cd1ad
9155862979f292ea527e4107a7143bd9b54c66511a1aa1b04a06f924a4ed901d
be9412060a9d41f496e907a637096255fa848a8ecb4bb4b35043f2e71ca871f6
8de72052a7f6f26cdf6b3a1850902acdd6856fe29b94871fd9eb3fceca479fa6
66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
5f97099c9597917ad3091e70910dc93ded0181185c1878fa4dfffaf540b46e4b
ccfaea5dfcfb212dff4902b0392b7b793bec6f56c5d7162fca472ed00995d381
c5f3533849c988dc9812857c7a8e6359d82cf650955eec6d14661426e62bbde1
fc555917ce12a41761d6e21ef399d5be7dce2da3d15a05b2ce3fff10abcd77f9
80b3c8d9dcccf09f2cd697875d417ecfd90dc7ce3132ef10bc5d6f48510d19da
185a716f245f4951e997e91ca747ec2f52acf4fb0adf594bccd9c8acbfacf677
b996d0418d6d8ac7d8f9ce4d09d0eb1f0fd1b30d733499742a41a9c6930521b4
e5406c9136408ddbe90ec00c45b1291e3e847826ce1be6c39b77327d135e57c2
8ef455d1383249717a5d6215a98c176da08d5cf9f2d70f6d3ea24368b36b00c5
038849db19818c7136fe0a551b3f1b9ab11d51390ab2f4197f9f7c5ff16f6a8f
987d80fbc03ed5f7612a742982367ae5f354237968d23b2fe1cbe9440946497d
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
01e631c29a801330b7eb8f5904e171a8d47b044754153792955a459c25db112b
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b
2f712c6b725905241f86c0a76963dc5053e59d0dbd1b0396dc2e88c3d94f54ff
1ec8e13c55c7d0114d1877cdce2e18be355218edce5ae2403ff928305799885b
5d19080b4f02064df1e03553721cb9269413ef21e5bee832d9dd5688f01db5e6
8de4312c046f3b3586dbf7a813d5678c2ad5dd319d476f4d64b403dc0d45f714
1e12346e4000bfaebac977089464afeb82b3729a90bb6ffd66dde49b2da297e2
8b903abd92011f515abe01bde91dbf27d2f8037e7712be038bf7bdad420b5e6e
ef522b08a1410eef91c4e03d3241eb012720d8e16ca363dd93a48c2b5c92df1f
f99d68393189fed84f6b667127e531a5f9efc410598335eb06a6b973462237e5
a5c29abda5dbd2006117b82fdadbb70f42354298b49019b73c36e31e8c6bdedb
7f4009e7a332b49ab49007e5cf74a87a6a7bf5a115a0acb621ff8657908ea2b3
81772deba6bfc78c34c1f83ecf47c84337e0b7592f96c6548b3e865a0a424eb3
0f0797053ff7a7b8e0bc5e75a5cd8e2eb91739101486374e4209c29a92fc2d66
SH256 hash:
59ddb47dbaf0572ca90303d5313a1c3924718d854f3d43ef3211a59383eb97f5
MD5 hash:
0cc5f325c73b53d4631d8d8701f354a3
SHA1 hash:
ad895cf8fb4ffe3d05c1046b81c7e3fad5a6f4b0
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
b9eae90f8e942cc4586d31dc484f29079651ad64c49f90d99f86932630c66af2
MD5 hash:
c0ef4d6237d106bf51c8884d57953f92
SHA1 hash:
f1da7ecbbee32878c19e53c7528c8a7a775418eb
SH256 hash:
65544a957f44347ba4b739d55e80caefcf0990a90d5856b7fa4893b3966db562
MD5 hash:
8adc85db12ea0d2cf1788a1a07da6234
SHA1 hash:
f8b2b09630007d56121473417464617bb3a9124a
Detections:
MAL_Envrial_Jan18_1 mal_xred_backdoor INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

DarkComet

Executable exe 9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments