General

  • Target

    26244e477fce74ab4e36e26e600a96b0_JaffaCakes118

  • Size

    205KB

  • Sample

    240508-w3vycaha7x

  • MD5

    26244e477fce74ab4e36e26e600a96b0

  • SHA1

    f2d51d793857e6d9829f24f711b37664cd737fa5

  • SHA256

    3c2382bdd0ace893cf833df5096a739330cd4f6cd1cc8e410634bdd166b5c776

  • SHA512

    f6e0525a3295613137d9a102d9fcf6cf052df90e9676b3c9d260bc5353656ce31fb515bfd6a133ee9858b865a34207388f156510b41920c8e0913fc411b47d5d

  • SSDEEP

    3072:KG1Q3vIG+2St2z8hvWHMeqhOOf4TpIgErI25:KG1UIG2DWHMeqUOQTng95

Score
10/10

Malware Config

Extracted

Family

buer

C2

https://rawcookies.ru/

https://westkingz.ru/

Targets

    • Target

      26244e477fce74ab4e36e26e600a96b0_JaffaCakes118

    • Size

      205KB

    • MD5

      26244e477fce74ab4e36e26e600a96b0

    • SHA1

      f2d51d793857e6d9829f24f711b37664cd737fa5

    • SHA256

      3c2382bdd0ace893cf833df5096a739330cd4f6cd1cc8e410634bdd166b5c776

    • SHA512

      f6e0525a3295613137d9a102d9fcf6cf052df90e9676b3c9d260bc5353656ce31fb515bfd6a133ee9858b865a34207388f156510b41920c8e0913fc411b47d5d

    • SSDEEP

      3072:KG1Q3vIG+2St2z8hvWHMeqhOOf4TpIgErI25:KG1UIG2DWHMeqUOQTng95

    Score
    10/10
    • Buer

      Buer is a new modular loader first seen in August 2019.

    • Modifies WinLogon for persistence

    • Buer Loader

      Detects Buer loader in memory or disk.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Peripheral Device Discovery

1
T1120

Tasks