SYMBOLCOMMON_NAMEaka. SYNONYMS
win.darkvnc (Back to overview)

DarkVNC

VTCollection    

According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online. it is can be used as a Virtual Network Computing service, which means that the attackers can get full access to the targeted system via this malware. However, unlike a genuine Virtual Network Computing utility, the DarkVNC threat operates in the background silently. Therefore, it is highly likely that the victims may not notice that their systems have been compromised.

References
2022-08-12 ⋅ SANS ISC ⋅ Brad Duncan
Monster Libra (TA551/Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike
Cobalt Strike DarkVNC IcedID
2022-07-27 ⋅ SANS ISC ⋅ Brad Duncan
IcedID (Bokbot) with Dark VNC and Cobalt Strike
DarkVNC IcedID
2017-11-08 ⋅ Reaqta ⋅ Reaqta
A short journey into DarkVNC attack chain
DarkVNC
Yara Rules
[TLP:WHITE] win_darkvnc_auto (20260917 | Detects win.darkvnc.)
rule win_darkvnc_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.darkvnc."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkvnc"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 85c0 7425 488b442458 8b4024 2500000080 85c0 740a }
            // n = 7, score = 100
            //   85c0                 | dec                 eax
            //   7425                 | mov                 edx, dword ptr [edx + 0x20]
            //   488b442458           | dec                 eax
            //   8b4024               | mov                 ecx, dword ptr [ecx + 0x10]
            //   2500000080           | inc                 esp
            //   85c0                 | mov                 eax, esi
            //   740a                 | mov                 ebx, esi

        $sequence_1 = { 488903 448bd6 0fb75504 488bc8 0fb77d06 450fb64e0a 48ffc7 }
            // n = 7, score = 100
            //   488903               | dec                 eax
            //   448bd6               | arpl                bx, bx
            //   0fb75504             | dec                 esp
            //   488bc8               | mov                 eax, ebx
            //   0fb77d06             | dec                 eax
            //   450fb64e0a           | add                 dword ptr [edi + 8], ebx
            //   48ffc7               | dec                 eax

        $sequence_2 = { 33d2 ff15???????? 4889abc0060000 4839ab98060000 7407 4889ab98060000 488b93a8060000 }
            // n = 7, score = 100
            //   33d2                 | lea                 edx, [0x15425]
            //   ff15????????         |                     
            //   4889abc0060000       | dec                 eax
            //   4839ab98060000       | lea                 ecx, [esp + 0x20]
            //   7407                 | dec                 eax
            //   4889ab98060000       | lea                 edx, [0x14e53]
            //   488b93a8060000       | dec                 eax

        $sequence_3 = { 488bf8 488bf1 b903000000 f3a4 488d44245b 488bf8 33c0 }
            // n = 7, score = 100
            //   488bf8               | dec                 ecx
            //   488bf1               | arpl                dx, cx
            //   b903000000           | dec                 eax
            //   f3a4                 | arpl                bx, dx
            //   488d44245b           | dec                 ebp
            //   488bf8               | add                 ecx, ebp
            //   33c0                 | dec                 ebp

        $sequence_4 = { 488d4c2420 ff15???????? 488d15035b0100 488d4c2420 ff15???????? 488b5368 488d4c2420 }
            // n = 7, score = 100
            //   488d4c2420           | cmova               eax, ebp
            //   ff15????????         |                     
            //   488d15035b0100       | dec                 ebp
            //   488d4c2420           | test                eax, eax
            //   ff15????????         |                     
            //   488b5368             | je                  0x1bd9
            //   488d4c2420           | dec                 ecx

        $sequence_5 = { 4803c8 48898fe0160000 488bcb e8???????? eb1d 488b05???????? 488bcb }
            // n = 7, score = 100
            //   4803c8               | mov                 eax, dword ptr [esp + 0x78]
            //   48898fe0160000       | je                  0xa91
            //   488bcb               | dec                 eax
            //   e8????????           |                     
            //   eb1d                 | mov                 dword ptr [esp + 0x38], 0
            //   488b05????????       |                     
            //   488bcb               | jmp                 0xa9a

        $sequence_6 = { c3 89542410 53 4883ec20 488b4108 488bd9 4883c004 }
            // n = 7, score = 100
            //   c3                   | mov                 dword ptr [esp + 0x20], 1
            //   89542410             | jmp                 0x1aab
            //   53                   | dec                 eax
            //   4883ec20             | mov                 eax, dword ptr [esp + 0x28]
            //   488b4108             | dec                 eax
            //   488bd9               | mov                 eax, dword ptr [eax + 8]
            //   4883c004             | dec                 eax

        $sequence_7 = { 488b0d???????? 4c8bc6 33d2 ff15???????? 4439a7a0020000 7429 ba11040000 }
            // n = 7, score = 100
            //   488b0d????????       |                     
            //   4c8bc6               | dec                 eax
            //   33d2                 | lea                 edx, [esp + 0x30]
            //   ff15????????         |                     
            //   4439a7a0020000       | mov                 dword ptr [esp + 0x30], 0x3c
            //   7429                 | dec                 eax
            //   ba11040000           | mov                 ecx, esi

        $sequence_8 = { 0f854b010000 488b942490000000 488bcf e8???????? 488be8 }
            // n = 5, score = 100
            //   0f854b010000         | mov                 eax, dword ptr [esp + 0xa0]
            //   488b942490000000     | dec                 esp
            //   488bcf               | mov                 edi, dword ptr [esp + 0xb0]
            //   e8????????           |                     
            //   488be8               | inc                 esp

        $sequence_9 = { 4c63742458 488b5c2450 4863e8 4c8bc5 488bd6 488bcb e8???????? }
            // n = 7, score = 100
            //   4c63742458           | mov                 edx, 1
            //   488b5c2450           | xor                 ecx, ecx
            //   4863e8               | dec                 esp
            //   4c8bc5               | lea                 ecx, [esp + 0xa0]
            //   488bd6               | inc                 ebp
            //   488bcb               | xor                 eax, eax
            //   e8????????           |                     

    condition:
        7 of them and filesize < 606208
}
Download all Yara Rules