File name:

Darkcomet RAT 5.3.1 crack.7z

Full analysis: https://app.any.run/tasks/58f086a1-3a7d-45f7-a0e5-aa009300d851
Verdict: Malicious activity
Threats:

DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.

Analysis date: February 09, 2022, 16:02:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
covid19
trojan
rat
darkcomet
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

F6ECBF8D93F1E829C1BC77FD7F735A61

SHA1:

69872C75C9C1D0AFEFCBA9428DCDA466999414F8

SHA256:

FBA49D700BE8B60F50C7B0B900D4365D168AED85382C746D3E8F8A24DE2EB21B

SSDEEP:

393216:VJHNZ/ICk1At4fZiXaugpe2Ms16Xhgeu21i:VJNZIC38ZiX2pMVds

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3600)
      • DarkComet.exe (PID: 3768)
    • Application was dropped or rewritten from another process

      • DarkCometUnpacker(delete after install).exe (PID: 4064)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
      • DarkComet.exe (PID: 3768)
      • 1.scr.scr (PID: 1032)
      • upnp.exe (PID: 2796)
      • msdcsc.exe (PID: 324)
    • Drops executable file immediately after starts

      • DarkCometUnpacker(delete after install).exe (PID: 2820)
      • 1.scr.scr (PID: 1032)
    • Changes the autorun value in the registry

      • 1.scr.scr (PID: 1032)
      • msdcsc.exe (PID: 324)
    • Changes the login/logoff helper path in the registry

      • 1.scr.scr (PID: 1032)
    • DARKCOMET was detected

      • msdcsc.exe (PID: 324)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 1236)
      • WinRAR.exe (PID: 2360)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
      • 1.scr.scr (PID: 1032)
      • upnp.exe (PID: 2796)
      • cmd.exe (PID: 3124)
      • DarkComet.exe (PID: 3768)
      • msdcsc.exe (PID: 324)
      • cmd.exe (PID: 1444)
    • Reads the computer name

      • WinRAR.exe (PID: 1236)
      • WinRAR.exe (PID: 2360)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
      • 1.scr.scr (PID: 1032)
      • DarkComet.exe (PID: 3768)
      • upnp.exe (PID: 2796)
      • msdcsc.exe (PID: 324)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2360)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2360)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
      • 1.scr.scr (PID: 1032)
      • DarkComet.exe (PID: 3768)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2360)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2360)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
    • Starts application with an unusual extension

      • DarkCometUnpacker(delete after install).exe (PID: 2820)
    • Starts CMD.EXE for commands execution

      • 1.scr.scr (PID: 1032)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 1444)
    • Reads the date of Windows installation

      • 1.scr.scr (PID: 1032)
    • Starts itself from another location

      • 1.scr.scr (PID: 1032)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2360)
      • DarkCometUnpacker(delete after install).exe (PID: 4064)
      • DarkCometUnpacker(delete after install).exe (PID: 2820)
    • Drops Coronavirus (possible) decoy

      • WinRAR.exe (PID: 2360)
    • Checks supported languages

      • attrib.exe (PID: 3588)
      • attrib.exe (PID: 3336)
      • notepad.exe (PID: 2564)
      • notepad.exe (PID: 2516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
15
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs darkcometunpacker(delete after install).exe no specs darkcometunpacker(delete after install).exe 1.scr.scr darkcomet.exe upnp.exe no specs cmd.exe no specs cmd.exe no specs notepad.exe attrib.exe no specs attrib.exe no specs #DARKCOMET msdcsc.exe notepad.exe

Process information

PID
CMD
Path
Indicators
Parent process
324"C:\Users\admin\Documents\MSDCSC\msdcsc.exe" C:\Users\admin\Documents\MSDCSC\msdcsc.exe
1.scr.scr
User:
admin
Company:
Microsoft Corp.
Integrity Level:
HIGH
Description:
Remote Service Application
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\documents\msdcsc\msdcsc.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1032"C:\Users\admin\AppData\Local\Temp\1.scr.scr" /SC:\Users\admin\AppData\Local\Temp\1.scr.scr
DarkCometUnpacker(delete after install).exe
User:
admin
Company:
Microsoft Corp.
Integrity Level:
HIGH
Description:
Remote Service Application
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\appdata\local\temp\1.scr.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1236"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack.7z"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
1444"C:\Windows\System32\cmd.exe" /k attrib "C:\Users\admin\AppData\Local\Temp" +s +hC:\Windows\System32\cmd.exe1.scr.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2360"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack.7z" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2516notepadC:\Windows\system32\notepad.exe
1.scr.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
3221225477
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2564notepadC:\Windows\system32\notepad.exe
msdcsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
3221225477
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
2796"C:\Users\admin\AppData\Local\Temp\upnp.exe" -a 192.168.100.62 4617 4617 TCPC:\Users\admin\AppData\Local\Temp\upnp.exeDarkComet.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\upnp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2820"C:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\DarkCometUnpacker(delete after install).exe" C:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\DarkCometUnpacker(delete after install).exe
Explorer.EXE
User:
admin
Company:
Unremote.org
Integrity Level:
HIGH
Description:
A remote administration tool from the cosmos
Exit code:
0
Version:
4.2.0.28
Modules
Images
c:\users\admin\desktop\darkcomet rat 5.3.1 crack\darkcometunpacker(delete after install).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3124"C:\Windows\System32\cmd.exe" /k attrib "C:\Users\admin\AppData\Local\Temp\1.scr.scr" +s +hC:\Windows\System32\cmd.exe1.scr.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 344
Read events
5 218
Write events
126
Delete events
0

Modification events

(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1236) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Operation:writeName:Band56_0
Value:
38000000730100000402000000000000D4D0C800000000000000000000000000540101000000000039000000B40200000000000001000000
Executable files
9
Suspicious files
133
Text files
50
Unknown types
4

Dropped files

PID
Process
Filename
Type
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Celesty Binder\config.iniini
MD5:FACE4F2A1F63AB5DAF4456E3A46F62DC
SHA256:E529BCDCCA95735AEE7020A3B26312560584B78394CE971B3A729823DD148AAA
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\config.iniini
MD5:
SHA256:
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\comet.dbsqlite
MD5:
SHA256:
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Celesty Binder\readme.txttext
MD5:EC0EB4AD970DC1D264BC6C6E7471428D
SHA256:BEC0F54669D35669D4E90E4AA588B96002B8A4E85048CE1CBF707F7F86AC250D
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Goodies\wallpaper_1.jpgimage
MD5:5B0F627CA05BE451F9A7AD52241DF3E3
SHA256:8977220BC72B4588DF3873044E6DD9BFAF166E48DA57386B4C152B72C8424185
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Goodies\wallpaper_2.jpgimage
MD5:1E10FDAA5D81BEC22F43B836F6EC2DE1
SHA256:5A9DC8D2E45FBC417522B04D097BB1FEC8CE75A827C497B403205601A4CD5B67
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Celesty Binder\Lang\EN.initext
MD5:D5B95D8DBCDCC5BE0290067BE9043009
SHA256:48A43817F513A7DE5F033F842EA71DCEC7CFE45E2EDC87BE844E461D99E2572E
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Icons\againzip.icoimage
MD5:B87DBD32F31532EA8F7AF9D28EE7800C
SHA256:C3C3B009CB602535C18ED168C0BC448441A62B63C69FF27E3F9C2D8973411250
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Celesty Binder\Lang\ES.initext
MD5:4745B84E71D23454D2535CC608DE57D0
SHA256:EB0553309ACD121B01566C1CA297ED46E896E3AD11C486971E8FA7275A1FF061
2360WinRAR.exeC:\Users\admin\Desktop\Darkcomet RAT 5.3.1 crack\Celesty Binder\Lang\AR.initext
MD5:4276808F92D3EFE8359CB03F9C45C9E1
SHA256:C4E0CD4D29594C9CB188DEAB7BB5F73FC6B3ED832468322ABC05B4E981C306C4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
25

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
324
msdcsc.exe
80.241.222.33:4617
Contabo GmbH
DE
malicious

DNS requests

No data

Threats

Found threats are available for the paid subscriptions
25 ETPRO signatures available at the full report
No debug info