General

  • Target

    563c7b884fca8f07414502e4b31b9a4a_JaffaCakes118

  • Size

    2.3MB

  • Sample

    240518-xc1xcaac26

  • MD5

    563c7b884fca8f07414502e4b31b9a4a

  • SHA1

    a58855aff0066e5291d2c0076cde31a5abcb6acc

  • SHA256

    eac16332d89309cec9208ac51a628f02f4abb70ed20243172ec492e1e1a317ca

  • SHA512

    8a91bb3f7a11b41e03f7e70e136d23bf52476c00215b9e765e04d1d6b6025967410709defa1704536e5feb6eb25f8495564b0a72fba90b88cb34633a28f6029a

  • SSDEEP

    49152:XIa+TGt8n9dp3vBs7qzU9CNOF9oCR8IsI:XIh6t85Iq3I3R87

Malware Config

Extracted

Family

danabot

C2

71.170.44.127

149.154.159.213

169.184.210.27

244.116.82.20

58.173.201.4

138.237.81.5

210.103.205.121

24.160.68.106

151.236.14.84

109.230.5.162

rsa_pubkey.plain

Targets

    • Target

      563c7b884fca8f07414502e4b31b9a4a_JaffaCakes118

    • Size

      2.3MB

    • MD5

      563c7b884fca8f07414502e4b31b9a4a

    • SHA1

      a58855aff0066e5291d2c0076cde31a5abcb6acc

    • SHA256

      eac16332d89309cec9208ac51a628f02f4abb70ed20243172ec492e1e1a317ca

    • SHA512

      8a91bb3f7a11b41e03f7e70e136d23bf52476c00215b9e765e04d1d6b6025967410709defa1704536e5feb6eb25f8495564b0a72fba90b88cb34633a28f6029a

    • SSDEEP

      49152:XIa+TGt8n9dp3vBs7qzU9CNOF9oCR8IsI:XIh6t85Iq3I3R87

    • Danabot

      Danabot is a modular banking Trojan that has been linked with other malware.

    • Danabot x86 payload

      Detection of Danabot x86 payload, mapped in memory during the execution of its loader.

    • Blocklisted process makes network request

    • Loads dropped DLL

MITRE ATT&CK Matrix

Tasks