General

  • Target

    989b40c26b532486a70f659a91532af7_JaffaCakes118

  • Size

    515KB

  • Sample

    240605-trcxaabg5w

  • MD5

    989b40c26b532486a70f659a91532af7

  • SHA1

    ab7382d83f917e5bc6df9d59994974899bf109a5

  • SHA256

    ef78f0a9adbce0219107853dc81c042274989f06ce947267cdd8485a56b4da46

  • SHA512

    c11ec14c57b371d0a45d6367ab0705b2fc4b11900bafdd54a9f0e61ff9cb041fb92594f70943445100a3aedc116c5e16dec5b5a8f3919930e5426f0d61830931

  • SSDEEP

    12288:sdIcOip5Tys7Egwkz3Fob/j9geUjpKxoDkNN7roE:kiLSEkz3avUjpy7cE

Malware Config

Extracted

Family

raccoon

Botnet

038d8533550cc2efd80d5d5f28d7b8f1ae07b0a3

Attributes
  • url4cnc

    https://drive.google.com/uc?export=download&id=1EpM5PfanjdCKrhBdxjnAx3nC77jXFBDm

rc4.plain
rc4.plain

Targets

    • Target

      989b40c26b532486a70f659a91532af7_JaffaCakes118

    • Size

      515KB

    • MD5

      989b40c26b532486a70f659a91532af7

    • SHA1

      ab7382d83f917e5bc6df9d59994974899bf109a5

    • SHA256

      ef78f0a9adbce0219107853dc81c042274989f06ce947267cdd8485a56b4da46

    • SHA512

      c11ec14c57b371d0a45d6367ab0705b2fc4b11900bafdd54a9f0e61ff9cb041fb92594f70943445100a3aedc116c5e16dec5b5a8f3919930e5426f0d61830931

    • SSDEEP

      12288:sdIcOip5Tys7Egwkz3Fob/j9geUjpKxoDkNN7roE:kiLSEkz3avUjpy7cE

    • Raccoon

      Raccoon is an infostealer written in C++ and first seen in 2019.

    • Raccoon Stealer V1 payload

    • Legitimate hosting services abused for malware hosting/C2

MITRE ATT&CK Matrix ATT&CK v13

Tasks