DarkOmen
It is a Keylogger. A key logger is a program that captures and logs keystrokes on the computer without the user's knowledge and consent. The logged data may be encrypted and is typically sent to a remote attacker. The key logger is usually hidden
from the user and may use cloaking (rootkit) technology to hide from other software in order to evade detection by anti-malware applications. Key loggers may be installed by trojans with other malicious software through exploits, and are often used
by online criminal gangs to facilitate identity theft and bank fraud operations.0
General information:
Malware Name: |
DarkOmen |
Malware Type: |
Key Logger |
Company Name: |
DARKOMEN |
Company URL: |
http://home.talkcity.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
DARKOMEN is a key logger for Windows built on a client/server model which allows a server to monitor a whole networks keystrokes. It has option for logs to be sent to predefined email Id's.
Spyware Description:
It is a Keylogger. A key logger is a program that captures and logs keystrokes on the computer without the user's knowledge and consent. The logged data may be encrypted and is typically sent to a remote attacker. The key logger is usually hidden
from the user and may use cloaking (rootkit) technology to hide from other software in order to evade detection by anti-malware applications. Key loggers may be installed by trojans with other malicious software through exploits, and are often used
by online criminal gangs to facilitate identity theft and bank fraud operations.0
Characteristics/Symptoms:
-> Starts with the operating system -> Run in stealth mode -> Monitor and capture data from computers -> Intercepts keystrokes from the keyboard and records them in a log0
Additional information might be found here:
Processes Running:
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Program Files\DarkOmen\DarkOmenWizard.exe |
180224 |
Application |
C:\Program Files\DarkOmen\Wizard.ico |
766 |
Icon |
C:\Program Files\DarkOmen\dat\hex.pak |
954589 |
PAK File |
Folder information Created after Installation:
Folder Location |
C:\Program Files\DarkOmen |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
SOFTWAREMicrosoftWindowsCurrentVersionUninstallDarkOmenWizard.exe |
DisplayName |