General

  • Target

    80dfcce79746fa5f6d6586963f2d0ea6_JaffaCakes118

  • Size

    1.4MB

  • Sample

    240402-cpa68sdg7w

  • MD5

    80dfcce79746fa5f6d6586963f2d0ea6

  • SHA1

    082c49491efda190daed58b44188bed03dcc78bf

  • SHA256

    cdc00a4d60058abdd666ddb7a283bf5eb57a668c08656e757f0faa5bf7d5007b

  • SHA512

    fbd9c0fddca8754e1df6f16a4966046b2a9e16ade6aeec9f5917699d47d755f1915cfd73ce3a0168b812708f081c47a5245d4b013032fa7613be5d7b4be64907

  • SSDEEP

    24576:wxpXPaR2J33o3S7P5zuHHOF2ahfehMHsGKzOYf8EEvX3yZ1rsa:Qpy+VDa8rtPvX3yZ9s

Malware Config

Extracted

Family

socelars

C2

http://www.iyiqian.com/

http://www.hbgents.top/

http://www.rsnzhy.com/

http://www.efxety.top/

Targets

    • Target

      80dfcce79746fa5f6d6586963f2d0ea6_JaffaCakes118

    • Size

      1.4MB

    • MD5

      80dfcce79746fa5f6d6586963f2d0ea6

    • SHA1

      082c49491efda190daed58b44188bed03dcc78bf

    • SHA256

      cdc00a4d60058abdd666ddb7a283bf5eb57a668c08656e757f0faa5bf7d5007b

    • SHA512

      fbd9c0fddca8754e1df6f16a4966046b2a9e16ade6aeec9f5917699d47d755f1915cfd73ce3a0168b812708f081c47a5245d4b013032fa7613be5d7b4be64907

    • SSDEEP

      24576:wxpXPaR2J33o3S7P5zuHHOF2ahfehMHsGKzOYf8EEvX3yZ1rsa:Qpy+VDa8rtPvX3yZ9s

    • Socelars

      Socelars is an infostealer targeting browser cookies and credit card credentials.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Legitimate hosting services abused for malware hosting/C2

    • Looks up geolocation information via web service

      Uses a legitimate geolocation service to find the infected system's geolocation info.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

1
T1005

Command and Control

Web Service

1
T1102

Tasks