Technical Analysis of DarkVision RAT
Common Information
Type Value
UUID c5c24303-7ef7-4b08-968b-dc352568fea2
Fingerprint 26b0981aa9e29bd3
Analysis status DONE
Considered CTI value 2
Text language
Published Oct. 10, 2024, 2:10 p.m.
Added to db Oct. 10, 2024, 4:42 p.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline Technical Analysis of DarkVision RAT
Title Technical Analysis of DarkVision RAT
Detected Hints/Tags/Attributes 92/3/29
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 158 Malware Analysis, News and Indicators - Latest topics https://malware.news/latest.rss 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 2
structure.one
Details Domain 2
rat.windows
Details Domain 2
rat.here
Details Domain 2
location.next
Details Domain 6
severdops.ddns.net
Details Domain 3
sample.in
Details Domain 2
indicatorstypeindicatordescriptionurlnasyiahgamping.com
Details Domain 2
stage.domainseverdops.ddns.net
Details File 2
plugins.key
Details File 3
c:\yknoahdrv.exe
Details File 4
yknoahdrv.exe
Details File 3
c:\users\redacted\appdata\roaming\siguhl.exe
Details File 3
siguhl.exe
Details File 4
%appdata%\sighul.exe
Details File 18
winsat.exe
Details File 14
dxgi.dll
Details File 2125
cmd.exe
Details File 1208
powershell.exe
Details File 4
%appdata%\photos\system.exe
Details File 2
8120.reg
Details File 2
disk.tab
Details File 2
executed.pl
Details File 2
description.pl
Details File 2
pid.tab
Details MITRE ATT&CK Techniques 207
T1547
Details MITRE ATT&CK Techniques 235
T1562
Details MITRE ATT&CK Techniques 152
T1056
Details Windows Registry Key 112
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Details Windows Registry Key 15
HKEY_CURRENT_USER\SOFTWARE