General

  • Target

    5830cf430af8122d01cf361078a6bb93_JaffaCakes118

  • Size

    324KB

  • Sample

    240519-dbd7eaeh42

  • MD5

    5830cf430af8122d01cf361078a6bb93

  • SHA1

    c696f0be9086fc97b757187d203519593a02ce12

  • SHA256

    05c33a3e8abc524778d307356dc4a540bdf864b307a0f2ecd4a60c72016b9cb6

  • SHA512

    79a5dd555ec3423911acb491fb8edaed0ac595d2327570521d6c2e8f337c63192e0dcf2ff46161324c763f721a66f25113363c7fbd06aba2ddb5f4a30fdde5a2

  • SSDEEP

    6144:lOLPO/z4Rgx/oIS7v91X/7buycO3UrYdE2DsHfC:Qi/z4R+kRNjblcOSYS2Qq

Malware Config

Extracted

Family

gcleaner

C2

gc-partners.in

Targets

    • Target

      5830cf430af8122d01cf361078a6bb93_JaffaCakes118

    • Size

      324KB

    • MD5

      5830cf430af8122d01cf361078a6bb93

    • SHA1

      c696f0be9086fc97b757187d203519593a02ce12

    • SHA256

      05c33a3e8abc524778d307356dc4a540bdf864b307a0f2ecd4a60c72016b9cb6

    • SHA512

      79a5dd555ec3423911acb491fb8edaed0ac595d2327570521d6c2e8f337c63192e0dcf2ff46161324c763f721a66f25113363c7fbd06aba2ddb5f4a30fdde5a2

    • SSDEEP

      6144:lOLPO/z4Rgx/oIS7v91X/7buycO3UrYdE2DsHfC:Qi/z4R+kRNjblcOSYS2Qq

    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • OnlyLogger

      A tiny loader that uses IPLogger to get its payload.

    • OnlyLogger payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks