MALICIOUS — 6ddb622e6fee1b17ac263a9c51d33be13acdfe2cd755f0b48ba0f484f1d0e521
MALICIOUS — 6ddb622e6fee1b17ac263a9c51d33be13acdfe2cd755f0b48ba0f484f1d0e521 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the DarkKomet family. 5 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
6ddb622e6fee1b17ac263a9c51d33be13acdfe2cd755f0b48ba0f484f1d0e521 - SHA-1:
4f84f9e5e2de2ab086746d0eb6ab6735f3d04383 - MD5:
3c815891d41b5477011807b240847537 - imphash:
deb20a65995a00ca52012c00eb814c26 - ssdeep:
196608:QWhK9KhKhKhK38hK9KhKhKhKL8hK9KhKhKhKl:g - TLSH:
T1BF6A8E30C3FDA007F56B9F026C25D88C168FF81AD457911902574283DAEE6D3E9B5A8E - Submitted as: 6ddb622e6fee1b17ac263a9c51d33be13acdfe2cd755f0b48ba0f484f1d0e521
- File type: pe · Size: 9444656 bytes
- Verdict: malicious (94/100) · Family: DarkKomet
Detections (5 of 52 engines)
- ClamAV (daily): Win.Dropper.DarkKomet-10025442-0
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: Trojan:MSIL/Aenjaris.S!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Jalapeno.18644
- Kaspersky (KVRT): HEUR:Trojan-Ransom.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Dropper.DarkKomet-10025442-0 (rule
Win.Dropper.DarkKomet-10025442-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://serverjarvis.sytes.net/resource_vir/command.php?version=0020 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://serverjarvis.sytes.net/resource_vir/command.php?version=0020
Embedded domains
- serverjarvis.sytes.net
Registry keys
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
More DarkKomet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report