s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-js.darkwatchman

📛 Threat Title

Malware family: DarkWatchman

Category: DarkWatchman First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.darkwatchman`. Printable name: DarkWatchman.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.darkwatchman VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.darkwatchman

IOC database

Type
domain
Value
js.darkwatchman
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.darkwatchman

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.darkwatchman

References (1)

Remediations (10)

  • web:attack.mitre.org

    DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021. [1]

  • web:cve.nohackme.com

    DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.

  • web:cybersecuritynews.com

    The distribution of DarkWatchman malware was being carried out by threat actors through this website. In the year 2021, DarkWatchman was initially detected, and its focus was primarily on users in Russia. The DarkWatchman RAT grants attackers unauthorized access to a victim's system.

  • web:ethicalhackingnews.substack.com

    The rise of nation-grade malware , exemplified by the DarkWatchman and Sheriff backdoors, underscores the growing concern of cybersecurity. As organizations continue to evolve their threat detection strategies, it is essential to stay vigilant and prioritize investments in robust security solutions.

  • web:malpedia.caad.fkie.fraunhofer.de

    js. darkwatchman (Back to overview) DarkWatchman Propose Change Prevailion found this RAT written in JavaScript, which dynamically compiles an accompanying keylogger written in C# and uses a DGA for C&C.

  • web:medium.com

    Analysis of DarkWatchman RAT (executable file) Summary The file is highly malicious and uses a lot of different techniques to bypass the system checks It is highly packed and uses SFX to as a …

  • web:thehackernews.com

    Phishing attacks deliver DarkWatchman and Sheriff malware ; targets span Russia, Ukraine, Baltics, with stealth and persistence tactics.

  • web:therecord.media

    A financially motivated group tracked as Hive0117 recently attacked multiple Russian industries with a retooled version of DarkWatchman malware , researchers said.

  • web:www.ibm.com

    A new phishing campaign conducted by Hive0117 was recently discovered, delivering the fileless malware called DarkWatchman . Explore the analysis from IBM X-Force researchers.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.