General

  • Target

    5cb1e75311bd45338d7c3daff1d841f2_JaffaCakes118

  • Size

    231KB

  • Sample

    240520-ctjn6sfg9t

  • MD5

    5cb1e75311bd45338d7c3daff1d841f2

  • SHA1

    460b6a6a4231419e241b6c82143cf763695d9116

  • SHA256

    3f70e988489df0e7eb8ff80460ad88e76464568113a451b8dd5bff16e39999c8

  • SHA512

    96cdf98c78633319a3874f958a7c79944ecc9c6eb8e854df96503ebf645ecb391236f72312fa3bf61528997162c59b1ff5b5d3e9dc2949e2c5c7cc1954cce57d

  • SSDEEP

    3072:9s9ACsqizZSKeysSle1FtGYkvDG0qG/0Bq3Vw7GiDA4h56e:e96blIEY6Jn/zeGi89

Malware Config

Extracted

Family

gcleaner

C2

gc-partners.in

Targets

    • Target

      5cb1e75311bd45338d7c3daff1d841f2_JaffaCakes118

    • Size

      231KB

    • MD5

      5cb1e75311bd45338d7c3daff1d841f2

    • SHA1

      460b6a6a4231419e241b6c82143cf763695d9116

    • SHA256

      3f70e988489df0e7eb8ff80460ad88e76464568113a451b8dd5bff16e39999c8

    • SHA512

      96cdf98c78633319a3874f958a7c79944ecc9c6eb8e854df96503ebf645ecb391236f72312fa3bf61528997162c59b1ff5b5d3e9dc2949e2c5c7cc1954cce57d

    • SSDEEP

      3072:9s9ACsqizZSKeysSle1FtGYkvDG0qG/0Bq3Vw7GiDA4h56e:e96blIEY6Jn/zeGi89

    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • OnlyLogger

      A tiny loader that uses IPLogger to get its payload.

    • OnlyLogger payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks