Source: 00000006.00000000.479399059.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000006.00000001.481410763.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000006.00000001.481410763.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000006.00000000.479399059.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000002.00000003.450764221.7F370000.00000004.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000005.00000002.491857687.02580000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000005.00000002.491857687.02580000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000002.00000002.462554403.025D0000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000002.00000002.462554403.025D0000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000003.00000001.447610474.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000003.00000001.447610474.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000003.00000002.699224479.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000003.00000002.699224479.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000006.00000000.479959577.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000006.00000000.479959577.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000006.00000002.482534154.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000006.00000002.482534154.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000003.00000000.446776706.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000003.00000000.446776706.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000005.00000003.485657484.7F370000.00000004.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 00000003.00000000.446217367.00400000.00000040.sdmp, type: MEMORY | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 00000003.00000000.446217367.00400000.00000040.sdmp, type: MEMORY | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.1.regdrv.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.1.regdrv.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 5.2.regdrv.exe.2580000.3.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 5.2.regdrv.exe.2580000.3.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.2.regdrv.exe.400000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.2.regdrv.exe.400000.3.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.0.regdrv.exe.400000.5.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.0.regdrv.exe.400000.5.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 2.2.regdrv.exe.25d0000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 2.2.regdrv.exe.25d0000.3.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 5.2.regdrv.exe.2580000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 5.2.regdrv.exe.2580000.3.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 2.2.regdrv.exe.25d0000.3.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 2.2.regdrv.exe.25d0000.3.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.0.regdrv.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.0.regdrv.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.1.regdrv.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.1.regdrv.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.2.regdrv.exe.400000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.2.regdrv.exe.400000.3.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.0.regdrv.exe.400000.5.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.0.regdrv.exe.400000.5.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.2.regdrv.exe.400000.3.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.2.regdrv.exe.400000.3.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.0.regdrv.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.0.regdrv.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.2.regdrv.exe.400000.3.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.2.regdrv.exe.400000.3.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.0.regdrv.exe.400000.5.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.0.regdrv.exe.400000.5.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.0.regdrv.exe.400000.4.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.0.regdrv.exe.400000.4.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.0.regdrv.exe.400000.5.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.0.regdrv.exe.400000.5.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 6.0.regdrv.exe.400000.4.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 6.0.regdrv.exe.400000.4.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.1.regdrv.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.1.regdrv.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: 3.1.regdrv.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Malware_QA_update date = 2016-08-29, hash2 = 6415b45f5bae6429dd5d92d6cae46e8a704873b7090853e68e80cd179058903e, author = Florian Roth, description = VT Research QA uploaded malware - file update.exe, reference = VT Research QA, license = https://creativecommons.org/licenses/by-nc/4.0/, score = 6d805533623d7063241620eec38b7eb9b625533ccadeaf4f6c2cc6db32711541 |
Source: 3.1.regdrv.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: RAT_DarkComet date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects DarkComet RAT, reference = http://malwareconfig.com/stats/DarkComet |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004865E0 Sleep,TranslateMessage,DispatchMessageA,PeekMessageA,socket,ntohs,inet_addr,gethostbyname,connect,recv,shutdown,closesocket, | 3_2_004865E0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004801FC socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,recv,send,recv,recv,recv,shutdown,closesocket, | 3_2_004801FC |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004821A0 socket,ExitThread,inet_addr,ntohs,gethostbyname,ExitThread,sendto,Sleep,closesocket,ExitThread, | 3_2_004821A0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0048851C socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,mouse_event,shutdown,closesocket, | 3_2_0048851C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00460628 inet_addr,ntohs, | 3_2_00460628 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00482630 socket,ExitThread,inet_addr,ntohs,gethostbyname,ExitThread,connect,ExitThread,recv,Sleep,closesocket,ExitThread, | 3_2_00482630 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004607A4 getservbyname,ntohs, | 3_2_004607A4 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00480880 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,shutdown,closesocket,shutdown,closesocket, | 3_2_00480880 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00486918 recv,recv,send,send,recv,send,send,send,send,send,recv,recv,recv,gethostbyname,ntohs,socket,connect,getsockname,send,select,recv,send,recv,send,Sleep,closesocket,closesocket, | 3_2_00486918 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0048298C socket,ExitThread,ntohs,inet_addr,gethostbyname,ExitThread,connect,closesocket,ExitThread,closesocket,ExitThread, | 3_2_0048298C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00486E2C socket,ntohs,bind,listen,accept,LocalAlloc,CreateThread,CloseHandle,Sleep,ExitThread, | 3_2_00486E2C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0048317C socket,ExitThread,ntohs,inet_addr,gethostbyname,ExitThread,connect,recv,recv,send,recv,shutdown,closesocket,ExitThread, | 3_2_0048317C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00489244 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,send,recv,shutdown,closesocket,ExitThread, | 3_2_00489244 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0047F4E0 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,recv,recv,shutdown,closesocket, | 3_2_0047F4E0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004836D8 socket,ExitThread,inet_addr,ntohs,gethostbyname,ExitThread,connect,ExitThread,recv,Sleep,closesocket,ExitThread, | 3_2_004836D8 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0047FA8C socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,GetDC,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetDeviceCaps,GetDeviceCaps,BitBlt,send,recv,SelectObject,DeleteObject,DeleteObject,ReleaseDC,shutdown,closesocket, | 3_2_0047FA8C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004801FC socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,recv,send,recv,recv,recv,shutdown,closesocket, | 6_2_004801FC |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004821A0 socket,ExitThread,inet_addr,ntohs,gethostbyname,ExitThread,sendto,Sleep,closesocket,ExitThread, | 6_2_004821A0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0048851C socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,mouse_event,shutdown,closesocket, | 6_2_0048851C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004865E0 Sleep,TranslateMessage,DispatchMessageA,PeekMessageA,socket,ntohs,inet_addr,gethostbyname,connect,recv,shutdown,closesocket, | 6_2_004865E0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00460628 inet_addr,ntohs, | 6_2_00460628 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00482630 socket,ExitThread,inet_addr,ntohs,gethostbyname,ExitThread,connect,ExitThread,recv,Sleep,closesocket,ExitThread, | 6_2_00482630 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004607A4 getservbyname,ntohs, | 6_2_004607A4 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00480880 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,shutdown,closesocket,shutdown,closesocket, | 6_2_00480880 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00486918 recv,recv,send,send,recv,send,send,send,send,send,recv,recv,recv,gethostbyname,ntohs,socket,connect,getsockname,send,select,recv,send,recv,send,Sleep,closesocket,closesocket, | 6_2_00486918 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0048298C socket,ExitThread,ntohs,inet_addr,gethostbyname,ExitThread,connect,closesocket,ExitThread,closesocket,ExitThread, | 6_2_0048298C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00486E2C socket,ntohs,bind,listen,accept,LocalAlloc,CreateThread,CloseHandle,Sleep,ExitThread, | 6_2_00486E2C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0048317C socket,ExitThread,ntohs,inet_addr,gethostbyname,ExitThread,connect,recv,recv,send,recv,shutdown,closesocket,ExitThread, | 6_2_0048317C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00489244 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,send,recv,shutdown,closesocket,ExitThread, | 6_2_00489244 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0047F4E0 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,recv,recv,shutdown,closesocket, | 6_2_0047F4E0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004836D8 socket,ExitThread,inet_addr,ntohs,gethostbyname,ExitThread,connect,ExitThread,recv,Sleep,closesocket,ExitThread, | 6_2_004836D8 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0047FA8C socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,GetDC,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetDeviceCaps,GetDeviceCaps,BitBlt,send,recv,SelectObject,DeleteObject,DeleteObject,ReleaseDC,shutdown,closesocket, | 6_2_0047FA8C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00487B54 CoInitialize,socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,send,recv,shutdown,closesocket, | 6_2_00487B54 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0047FE20 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,send,shutdown,closesocket, | 6_2_0047FE20 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00485F40 socket,ntohs,inet_addr,gethostbyname,connect,recv,recv, | 6_2_00485F40 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00487F2C socket,ntohs,inet_addr,gethostbyname,connect,recv,recv,recv,Sleep,send,recv,shutdown,closesocket, | 6_2_00487F2C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00473F34 CreateProcessA,GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,VirtualFree,TerminateProcess, | 6_2_00473F34 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034D07E | 1_3_0034D07E |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034D9FC | 1_3_0034D9FC |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_00347200 | 1_3_00347200 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034D29E | 1_3_0034D29E |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_00351331 | 1_3_00351331 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034DBD8 | 1_3_0034DBD8 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034D4BC | 1_3_0034D4BC |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034CCD1 | 1_3_0034CCD1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034D566 | 1_3_0034D566 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034D568 | 1_3_0034D568 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034CDD6 | 1_3_0034CDD6 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_00347DCA | 1_3_00347DCA |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034AFC9 | 1_3_0034AFC9 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_004021D8 | 1_2_004021D8 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034AFD4 | 1_3_0034AFD4 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 2_2_004021D8 | 2_2_004021D8 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_00402370 | 3_2_00402370 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004064C0 | 3_2_004064C0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0043E644 | 3_2_0043E644 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_004389B4 | 3_2_004389B4 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0045EC78 | 3_2_0045EC78 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0046ADBC | 3_2_0046ADBC |
Source: C:\Users\user\Music\regdrv.exe | Code function: 3_2_0046797C | 3_2_0046797C |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B087E | 4_3_002B087E |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B11FC | 4_3_002B11FC |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002AAA00 | 4_3_002AAA00 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B0A9E | 4_3_002B0A9E |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B4B31 | 4_3_002B4B31 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B13D8 | 4_3_002B13D8 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B0CBC | 4_3_002B0CBC |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B04D1 | 4_3_002B04D1 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B0D68 | 4_3_002B0D68 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B0D66 | 4_3_002B0D66 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002AB5CA | 4_3_002AB5CA |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002B05D6 | 4_3_002B05D6 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002AE7C9 | 4_3_002AE7C9 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_2_004021D8 | 4_2_004021D8 |
Source: C:\Users\user\Videos\Regdriver.exe | Code function: 4_3_002AE7D4 | 4_3_002AE7D4 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 5_2_004021D8 | 5_2_004021D8 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00402370 | 6_2_00402370 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004064C0 | 6_2_004064C0 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0043E644 | 6_2_0043E644 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_004389B4 | 6_2_004389B4 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0045EC78 | 6_2_0045EC78 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0046ADBC | 6_2_0046ADBC |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_0046797C | 6_2_0046797C |
Source: C:\Users\user\Music\regdrv.exe | Code function: 6_2_00469B90 | 6_2_00469B90 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_00344D14 push 00344D51h; ret | 1_3_00344D49 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_003421DD push eax; ret | 1_3_00342219 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034C1D9 push esp; retn 0034h | 1_3_0034C1E9 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034E24C push ecx; mov dword ptr [esp], edx | 1_3_0034E251 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_003422AD push 003424B9h; ret | 1_3_003424B1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034FB3C push ebx; ret | 1_3_0034FB5D |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034FB3C push eax; ret | 1_3_0034FB81 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034232E push 003424B9h; ret | 1_3_003424B1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_003423AB push 003424B9h; ret | 1_3_003424B1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_00342410 push 003424B9h; ret | 1_3_003424B1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0035049E push eax; ret | 1_3_003504CB |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034CCD1 push ecx; mov dword ptr [esp], edx | 1_3_0034CCF1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_0034CDD6 push ecx; mov dword ptr [esp], edx | 1_3_0034CDDD |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_3_00347DCA push ecx; mov dword ptr [esp], eax | 1_3_00347DE1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0040E17C push ecx; mov dword ptr [esp], edx | 1_2_0040E181 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0041F100 push ecx; mov dword ptr [esp], edx | 1_2_0041F105 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0041B238 push ecx; mov dword ptr [esp], edx | 1_2_0041B23A |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_004172A8 push ecx; mov dword ptr [esp], edx | 1_2_004172AD |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_004194A4 push ecx; mov dword ptr [esp], edx | 1_2_004194A5 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_00417504 push ecx; mov dword ptr [esp], edx | 1_2_00417509 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_00417668 push ecx; mov dword ptr [esp], edx | 1_2_0041766D |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_00417624 push ecx; mov dword ptr [esp], edx | 1_2_00417629 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0041E6B0 push ecx; mov dword ptr [esp], edx | 1_2_0041E6B2 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0041577C push 004157C9h; ret | 1_2_004157C1 |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0040E816 push 0040EAC2h; ret | 1_2_0040EABA |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_00403B70 push eax; ret | 1_2_00403BAC |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_00414D6E push 00414DE6h; ret | 1_2_00414DDE |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_0041FE36 push 0041FEE3h; ret | 1_2_0041FEDB |
Source: C:\Users\user\Desktop\DOC000YUT600.exe | Code function: 1_2_00406E8E push 00406EEBh; ret | 1_2_00406EE3 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 2_2_0040E17C push ecx; mov dword ptr [esp], edx | 2_2_0040E181 |
Source: C:\Users\user\Music\regdrv.exe | Code function: 2_2_0041F100 push ecx; mov dword ptr [esp], edx | 2_2_0041F105 |