General

  • Target

    9401b310cf409b2efb41d4829241259c_JaffaCakes118

  • Size

    120KB

  • Sample

    240604-jaslashe2x

  • MD5

    9401b310cf409b2efb41d4829241259c

  • SHA1

    e00b95c4a66a6970a238e61b47fa00dc3c3e1942

  • SHA256

    5b3fc1ff5d1316a44070c434404d0293c76742cb8168400e5d79431df9f7b7ef

  • SHA512

    7ff25eb8d693f9fc933451028581d2436c701ddfab15d8fd10d4d6070683124dcad05978d2c920a3351eba131c3130871508e5280f4edb1d27c873d007c148f5

  • SSDEEP

    3072:za+dUDMZJjkzSzh25YohAUwr3XnsOOujmZOta:wMZSzSzhA1rwDXnhZCSa

Malware Config

Extracted

Family

icedid

C2

loadwe4.casa

Targets

    • Target

      9401b310cf409b2efb41d4829241259c_JaffaCakes118

    • Size

      120KB

    • MD5

      9401b310cf409b2efb41d4829241259c

    • SHA1

      e00b95c4a66a6970a238e61b47fa00dc3c3e1942

    • SHA256

      5b3fc1ff5d1316a44070c434404d0293c76742cb8168400e5d79431df9f7b7ef

    • SHA512

      7ff25eb8d693f9fc933451028581d2436c701ddfab15d8fd10d4d6070683124dcad05978d2c920a3351eba131c3130871508e5280f4edb1d27c873d007c148f5

    • SSDEEP

      3072:za+dUDMZJjkzSzh25YohAUwr3XnsOOujmZOta:wMZSzSzhA1rwDXnhZCSa

    • IcedID, BokBot

      IcedID is a banking trojan capable of stealing credentials.

    • IcedID First Stage Loader

MITRE ATT&CK Matrix

Tasks