TF-MAL-js.darkwatchman
📛 Threat Title
Malware family: DarkWatchman
Description
ThreatFox malware family `js.darkwatchman`. Printable name: DarkWatchman.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.darkwatchman
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.darkwatchman
IOC database
- Type
- domain
- Value
js.darkwatchman- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.darkwatchman
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.darkwatchman
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021. [1]
-
web:cve.nohackme.com
DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.
-
web:cybersecuritynews.com
The distribution of DarkWatchman malware was being carried out by threat actors through this website. In the year 2021, DarkWatchman was initially detected, and its focus was primarily on users in Russia. The DarkWatchman RAT grants attackers unauthorized access to a victim's system.
-
web:ethicalhackingnews.substack.com
The rise of nation-grade malware , exemplified by the DarkWatchman and Sheriff backdoors, underscores the growing concern of cybersecurity. As organizations continue to evolve their threat detection strategies, it is essential to stay vigilant and prioritize investments in robust security solutions.
-
web:malpedia.caad.fkie.fraunhofer.de
js. darkwatchman (Back to overview) DarkWatchman Propose Change Prevailion found this RAT written in JavaScript, which dynamically compiles an accompanying keylogger written in C# and uses a DGA for C&C.
-
web:medium.com
Analysis of DarkWatchman RAT (executable file) Summary The file is highly malicious and uses a lot of different techniques to bypass the system checks It is highly packed and uses SFX to as a …
-
web:thehackernews.com
Phishing attacks deliver DarkWatchman and Sheriff malware ; targets span Russia, Ukraine, Baltics, with stealth and persistence tactics.
-
web:therecord.media
A financially motivated group tracked as Hive0117 recently attacked multiple Russian industries with a retooled version of DarkWatchman malware , researchers said.
-
web:www.ibm.com
A new phishing campaign conducted by Hive0117 was recently discovered, delivering the fileless malware called DarkWatchman . Explore the analysis from IBM X-Force researchers.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.