General

  • Target

    0ee1a729d1a6c71cfadba80a7a166f93_JaffaCakes118

  • Size

    405KB

  • Sample

    240328-ytntsafc7x

  • MD5

    0ee1a729d1a6c71cfadba80a7a166f93

  • SHA1

    1379d3377cfe5617234b225243b8c57db0e4e1c8

  • SHA256

    09185e4fe865342754563f1c4198c13fc8f0bc6854021bb3b75bbf48021e0a34

  • SHA512

    f834684cf9d327b826db69695a747b4aed7afe87793d6a2d5f6c8337c73158c103ddb3d703fb4b05b3a59021fa3af100252c76acd5299086d65000b3c88f1fb2

  • SSDEEP

    6144:JIrSoNdo0gKprnb8xSxcDOW1Ga5YQXGzteOiw2wszZDPJReqDd/SYQK:uN0dQFxUOMG0XGztebw2wsdDuqDd/S

Malware Config

Extracted

Family

cryptbot

C2

befhns72.top

moralv07.top

Attributes
  • payload_url

    http://minets10.top/download.php?file=lv.exe

Targets

    • Target

      0ee1a729d1a6c71cfadba80a7a166f93_JaffaCakes118

    • Size

      405KB

    • MD5

      0ee1a729d1a6c71cfadba80a7a166f93

    • SHA1

      1379d3377cfe5617234b225243b8c57db0e4e1c8

    • SHA256

      09185e4fe865342754563f1c4198c13fc8f0bc6854021bb3b75bbf48021e0a34

    • SHA512

      f834684cf9d327b826db69695a747b4aed7afe87793d6a2d5f6c8337c73158c103ddb3d703fb4b05b3a59021fa3af100252c76acd5299086d65000b3c88f1fb2

    • SSDEEP

      6144:JIrSoNdo0gKprnb8xSxcDOW1Ga5YQXGzteOiw2wszZDPJReqDd/SYQK:uN0dQFxUOMG0XGztebw2wsdDuqDd/S

    • CryptBot

      A C++ stealer distributed widely in bundle with other software.

    • Deletes itself

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

2
T1005

Tasks