General

  • Target

    364a15d8bb0ffb21e6b7dd650eb12b0b_JaffaCakes118

  • Size

    16KB

  • Sample

    240511-yp2j3seg31

  • MD5

    364a15d8bb0ffb21e6b7dd650eb12b0b

  • SHA1

    d0db53c0e2e9f4e2ac87ea879d50775b20114754

  • SHA256

    fa5bbde6bc224e578b7eb2e4ea1506570b378279b4c5f79185043d15cc81b419

  • SHA512

    51f24d29c20af9a8d75e5dd17e2e8cd7a09e196cda55442b6c502b1ac7f6ba7e89e5ceb448ecf10ca2b954be22f80c3e784ef8e122b97aa5cc276087f8696638

  • SSDEEP

    384:e+FvJsPhdH19GTXjdhk1uujYcV6AUwJFZb:eAkfV9AhAfYcV6Dw9b

Malware Config

Extracted

Family

loaderbot

C2

http://s0rick.rckl.pw/cmd.php

Targets

    • Target

      364a15d8bb0ffb21e6b7dd650eb12b0b_JaffaCakes118

    • Size

      16KB

    • MD5

      364a15d8bb0ffb21e6b7dd650eb12b0b

    • SHA1

      d0db53c0e2e9f4e2ac87ea879d50775b20114754

    • SHA256

      fa5bbde6bc224e578b7eb2e4ea1506570b378279b4c5f79185043d15cc81b419

    • SHA512

      51f24d29c20af9a8d75e5dd17e2e8cd7a09e196cda55442b6c502b1ac7f6ba7e89e5ceb448ecf10ca2b954be22f80c3e784ef8e122b97aa5cc276087f8696638

    • SSDEEP

      384:e+FvJsPhdH19GTXjdhk1uujYcV6AUwJFZb:eAkfV9AhAfYcV6Dw9b

    • LoaderBot

      LoaderBot is a loader written in .NET downloading and executing miners.

    • LoaderBot executable

    • Drops startup file

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

Modify Registry

1
T1112

Tasks