Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with DarkWatchman

Database Entry


Malware:DarkWatchman
First seen:2022-01-31 00:54:11 UTC
Last seen:2022-07-27 07:47:28 UTC

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2022-07-27 07:47:28e8bc8cb386d478fba30ba27fb40f48c9Virustotal results 17 / 70 (24.29%) DarkWatchman193.37.213.16:443
2022-01-31 02:24:42326cf130af4754ee9c6e6cc8c7e802c8Virustotal results 20 / 68 (29.41%) DarkWatchman103.153.157.33:443
2022-01-31 02:24:42326cf130af4754ee9c6e6cc8c7e802c8Virustotal results 20 / 68 (29.41%) DarkWatchman103.153.157.33:443
2022-01-31 00:54:11a79adc37a723dd89014f01158a19ceccVirustotal results 22 / 64 (34.38%) DarkWatchman139.162.103.105:443
2022-01-31 00:54:11a79adc37a723dd89014f01158a19ceccVirustotal results 22 / 64 (34.38%) DarkWatchman139.162.103.105:443