General

  • Target

    2af5a00d00befdcbc1a04d8a993ddfeb_JaffaCakes118

  • Size

    227KB

  • Sample

    240509-vhe6qaff93

  • MD5

    2af5a00d00befdcbc1a04d8a993ddfeb

  • SHA1

    838211204c6a17149aa027882d4be61c4b29ce33

  • SHA256

    4ce6cd07bcac1f637e4b5202c91957d3b3d0f77c19dbe53e0ef30f7baf766f39

  • SHA512

    866efcf751fe16d1607a17d16248b9bf68127f455a90c485628d7d45fce7155b705b38882e6bad83c9c926b5fad3189914e08312aa775b481678daf5dd5fc97b

  • SSDEEP

    6144:/XPJatRoWtse+j/NZTEO4qyEKI7NvS/LBDqB54XB:JMWWtx8jrBNKlD64XB

Malware Config

Extracted

Family

gcleaner

C2

gc-partners.in

Targets

    • Target

      2af5a00d00befdcbc1a04d8a993ddfeb_JaffaCakes118

    • Size

      227KB

    • MD5

      2af5a00d00befdcbc1a04d8a993ddfeb

    • SHA1

      838211204c6a17149aa027882d4be61c4b29ce33

    • SHA256

      4ce6cd07bcac1f637e4b5202c91957d3b3d0f77c19dbe53e0ef30f7baf766f39

    • SHA512

      866efcf751fe16d1607a17d16248b9bf68127f455a90c485628d7d45fce7155b705b38882e6bad83c9c926b5fad3189914e08312aa775b481678daf5dd5fc97b

    • SSDEEP

      6144:/XPJatRoWtse+j/NZTEO4qyEKI7NvS/LBDqB54XB:JMWWtx8jrBNKlD64XB

    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • OnlyLogger

      A tiny loader that uses IPLogger to get its payload.

    • OnlyLogger payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks