Technical Analysis of DarkVision RAT
Common Information
Type Value
UUID 0c59b8a5-8ae6-47ef-894d-cf1498e1826d
Fingerprint 26b0981aa9e29b93
Analysis status DONE
Considered CTI value 2
Text language
Published Oct. 10, 2024, 10:09 a.m.
Added to db Oct. 10, 2024, 10:36 p.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline Technical Analysis of DarkVision RAT
Title Technical Analysis of DarkVision RAT
Detected Hints/Tags/Attributes 94/3/36
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 226 Security Boulevard https://securityboulevard.com/feed 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 2
structure.one
Details Domain 2
rat.windows
Details Domain 2
rat.here
Details Domain 2
location.next
Details Domain 6
severdops.ddns.net
Details Domain 3
sample.in
Details Domain 2
indicatorstypeindicatordescriptionurlnasyiahgamping.com
Details Domain 2
stage.domainseverdops.ddns.net
Details Domain 84
www.zscaler.com
Details File 2
plugins.key
Details File 4
yknoahdrv.exe
Details File 1
usersredactedappdataroamingsiguhl.exe
Details File 3
siguhl.exe
Details File 1
%appdata%sighul.exe
Details File 18
winsat.exe
Details File 14
dxgi.dll
Details File 2125
cmd.exe
Details File 1208
powershell.exe
Details File 1
%appdata%photossystem.exe
Details File 3
c:\yknoahdrv.exe
Details File 3
c:\users\redacted\appdata\roaming\siguhl.exe
Details File 4
%appdata%\sighul.exe
Details File 4
%appdata%\photos\system.exe
Details File 2
8120.reg
Details File 2
disk.tab
Details File 2
executed.pl
Details File 2
description.pl
Details File 2
pid.tab
Details MITRE ATT&CK Techniques 207
T1547
Details MITRE ATT&CK Techniques 235
T1562
Details MITRE ATT&CK Techniques 152
T1056
Details Url 2
https://www.zscaler.com/blogs/security-research/technical-analysis-darkvision-rat
Details Windows Registry Key 5
HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun
Details Windows Registry Key 1
HKEY_CURRENT_USERSOFTWARE
Details Windows Registry Key 112
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Details Windows Registry Key 15
HKEY_CURRENT_USER\SOFTWARE