File name:

Darkcomet RAT 5.3.1.zip

Full analysis: https://app.any.run/tasks/ed2d794e-5771-45cd-8f06-5ac66d438e42
Verdict: Malicious activity
Threats:

DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.

Analysis date: February 15, 2024, 16:14:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
covid19
darkcomet
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

9F9347ECF2CC6541FB64ACD6FC0A5749

SHA1:

6C0D454EC2068D1C7D502A167CA02C8DAFD0B244

SHA256:

BFE9A76229E6E502B7C542007CD976DD3B5E0D26190CDF7CC8A5E5AAB0A63F7D

SSDEEP:

393216:Yia1rsEqp8mxBktqBEH3JM/qbxhbRLEJt5RXtW3hg:Yl1rsEqJxChH3coxhbePK3hg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DarkComet.exe (PID: 3660)
      • WinRAR.exe (PID: 3240)
    • DARKCOMET has been detected (YARA)

      • DarkComet.exe (PID: 3660)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • DarkComet.exe (PID: 3660)
    • Executable content was dropped or overwritten

      • DarkComet.exe (PID: 3660)
    • Reads the Internet Settings

      • DarkComet.exe (PID: 3660)
  • INFO

    • Checks supported languages

      • DarkComet.exe (PID: 3660)
      • upnp.exe (PID: 3228)
    • Drops a (possible) Coronavirus decoy

      • WinRAR.exe (PID: 3240)
    • Reads the computer name

      • DarkComet.exe (PID: 3660)
      • upnp.exe (PID: 3228)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3240)
    • Manual execution by a user

      • DarkComet.exe (PID: 3660)
    • Create files in a temporary directory

      • DarkComet.exe (PID: 3660)
    • Reads the machine GUID from the registry

      • DarkComet.exe (PID: 3660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:02:25 11:40:32
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Darkcomet RAT 5.3.1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe #DARKCOMET darkcomet.exe upnp.exe

Process information

PID
CMD
Path
Indicators
Parent process
3228"C:\Users\admin\AppData\Local\Temp\upnp.exe" -a 192.168.100.132 1604 1604 TCPC:\Users\admin\AppData\Local\Temp\upnp.exe
DarkComet.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\upnp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
3240"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Darkcomet RAT 5.3.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3660"C:\Users\admin\Desktop\Darkcomet RAT 5.3.1\DarkComet.exe" C:\Users\admin\Desktop\Darkcomet RAT 5.3.1\DarkComet.exe
explorer.exe
User:
admin
Company:
Unremote.org
Integrity Level:
MEDIUM
Description:
A remote administration tool from the cosmos
Exit code:
0
Version:
4.2.0.28
Modules
Images
c:\users\admin\desktop\darkcomet rat 5.3.1\darkcomet.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
8 424
Read events
8 384
Write events
40
Delete events
0

Modification events

(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3240) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Darkcomet RAT 5.3.1.zip
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3240) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
79
Text files
49
Unknown types
56

Dropped files

PID
Process
Filename
Type
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\IT.inibinary
MD5:1CB447996787264785C83D110C67AB13
SHA256:840DB2223BC47B37C44393BCE4CA8583D373EF6D70B6BC9143561190AA16CDCB
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\FR.initext
MD5:A8568B41DF3F0A47F875964E8FEEFA70
SHA256:F515EE7D43CF301FE771599C60E2771DB6F27E614AF6A4403771A0D99CB19BC7
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Celesty.exeexecutable
MD5:C3009EE63BC661D9EA75EAEB256448CA
SHA256:0BB88564A22BFD6D9AD6E4D8EFA9077792A7B6094C2A0F865D70C43E11507352
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\SE.initext
MD5:A1EDF15F421E4735C5701F0EA648B35D
SHA256:19E6EC75FBAADE63C3CF862F08C7C736DE9374521B377CE3CFE55D23970381DA
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\AR.initext
MD5:4276808F92D3EFE8359CB03F9C45C9E1
SHA256:C4E0CD4D29594C9CB188DEAB7BB5F73FC6B3ED832468322ABC05B4E981C306C4
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\EN.initext
MD5:D5B95D8DBCDCC5BE0290067BE9043009
SHA256:48A43817F513A7DE5F033F842EA71DCEC7CFE45E2EDC87BE844E461D99E2572E
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\SR.initext
MD5:FDFC0EE3AD0F395E3078F600ED9BA689
SHA256:37DCDA2CD0682A3EDFE354111E0DD637BE6581A71E6C240AE5729CE9F6A05EF9
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\VN.initext
MD5:24874C298B575AE2AC496765AA5F3F6B
SHA256:B0B6AD746697E54CC76DCE834D963885D0284CCEEEB24DE62BE9EAF4BEE47EDD
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\changelog.txttext
MD5:7A23E5B811DD52E99CBDB72A7FE4CE12
SHA256:7CF268D2FBBC3BB3E1CE2019D53F7C88B42F3BBCD4833AC69798D34FBD809DFE
3240WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3240.16291\Darkcomet RAT 5.3.1\Celesty Binder\Lang\GR.initext
MD5:8B35CDF90F3D89D2502E1F61B2BBF631
SHA256:FCA01673CB23ABD479B6D54D19A40A87E9D72B90ECC7F5D59AF14D192CC07C7C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3228
upnp.exe
239.255.255.250:1900
unknown

DNS requests

No data

Threats

No threats detected
No debug info