DarkMegi rootkit - sample (distributed via Blackhole)
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Rootkit - T1014 Rootkit |
Common Information
Type | Value |
---|---|
UUID | 5e0e4fce-3a48-4b7c-a3d7-7feddd4f7416 |
Fingerprint | a81a617c16fb0c89 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | April 18, 2012, 9:57 p.m. |
Added to db | Sept. 26, 2022, 9:30 a.m. |
Last updated | Nov. 17, 2024, 10:40 p.m. |
Headline | UNKNOWN |
Title | DarkMegi rootkit - sample (distributed via Blackhole) |
Detected Hints/Tags/Attributes | 32/2/35 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 30 | www.msn.com |
|
Details | Domain | 52 | msn.com |
|
Details | Domain | 1 | w32.agent.77312.vc |
|
Details | File | 1 | c:\windows\system32\drivers\com32.sys |
|
Details | File | 1 | c:\windows\system32\drivers\rcx50e3.tmp |
|
Details | File | 1 | c:\windows\system32\rcx5b11.tmp |
|
Details | File | 1 | c:\windows\system32\del043.bat |
|
Details | File | 3 | c.gif |
|
Details | File | 1 | 2fdefaultwpe3w.aspx |
|
Details | File | 1 | dec3f3d671e6cc76b09340612a38.jpg |
|
Details | File | 1 | defaultwpe3w.aspx |
|
Details | File | 1 | 4b835e56ac3c8535db16275b4baf4.jpg |
|
Details | File | 1 | 756a1c963a72e4afbc36501b512725.jpg |
|
Details | File | 1 | f757c6dff15796123fa81cf7dccf.jpg |
|
Details | File | 2 | qsonhs.aspx |
|
Details | File | 1 | 440.swf |
|
Details | File | 1 | 175.jpg |
|
Details | md5 | 1 | 6C8F9658A390C24A9F4551DC15063927 |
|
Details | md5 | 1 | 4399b8a60977814197feae67c02a7ac2 |
|
Details | md5 | 1 | 9f32c51764f579512810b7ab3de1a91a |
|
Details | md5 | 1 | dd313b92f60bb66d3d613bc49c1ef35e |
|
Details | md5 | 1 | 25cfb72df8a30cbb7e6ee852bc31c50f |
|
Details | md5 | 1 | 2f00e0927c07bc44d9b79ccbe567f398 |
|
Details | md5 | 1 | 1a1e7855edc0afa6624080d60da8bf44 |
|
Details | md5 | 1 | 4571d83250544049bfc2ee88060f6bc8 |
|
Details | md5 | 1 | 23A3C63D37E16EEA2397C50633E16E45 |
|
Details | md5 | 1 | 6c8f9658a390c24a9f4551dc15063927 |
|
Details | sha1 | 1 | c1af1fa6937097762824d0db039777ff35577727 |
|
Details | sha256 | 1 | a2c176ef3cc343194207e33acc19d5f8cb083a3c387a0404bd8f9d6bd29cfd6f |
|
Details | IPv4 | 1 | 65.55.253.27 |
|
Details | IPv4 | 1 | 192.168.254.192 |
|
Details | IPv4 | 1 | 207.46.193.176 |
|
Details | IPv4 | 1 | 65.55.239.146 |
|
Details | Url | 6 | http://www.msn.com |
|
Details | Url | 1 | http://www.msn.com/defaultwpe3w.aspx |