General

  • Target

    38d38fb6a44235ff2e6ee0096ea4304c_JaffaCakes118

  • Size

    68KB

  • Sample

    240512-hq12yadf2w

  • MD5

    38d38fb6a44235ff2e6ee0096ea4304c

  • SHA1

    bea3f80d26bc5f9f92cb662ad68805b086f16aa0

  • SHA256

    81ebc53905826f9edb4960d3a678196038f5be2f0c145468f8391232ed6793c6

  • SHA512

    1c8ebe32feaaa526fff4f2da9c1dc43c251ad952441baa37aa51ad3a7ad852e6a73b1eadf51d79313e0d20842018328439de782300a155eb8e2168cceeffe9eb

  • SSDEEP

    1536:Y8dQ2vQRYW7k6s/gk4A+XZgPTpQRohL1ZXR6wGM:btq73seA+SPM2swGM

Malware Config

Extracted

Family

hancitor

Botnet

25neo02

C2

http://toffithatwith.com/4/forum.php

http://howdirena.ru/4/forum.php

http://tosinheet.ru/4/forum.php

Targets

    • Target

      38d38fb6a44235ff2e6ee0096ea4304c_JaffaCakes118

    • Size

      68KB

    • MD5

      38d38fb6a44235ff2e6ee0096ea4304c

    • SHA1

      bea3f80d26bc5f9f92cb662ad68805b086f16aa0

    • SHA256

      81ebc53905826f9edb4960d3a678196038f5be2f0c145468f8391232ed6793c6

    • SHA512

      1c8ebe32feaaa526fff4f2da9c1dc43c251ad952441baa37aa51ad3a7ad852e6a73b1eadf51d79313e0d20842018328439de782300a155eb8e2168cceeffe9eb

    • SSDEEP

      1536:Y8dQ2vQRYW7k6s/gk4A+XZgPTpQRohL1ZXR6wGM:btq73seA+SPM2swGM

    • Hancitor

      Hancitor is downloader used to deliver other malware families.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix

Tasks