General

  • Target

    993333c113dec2b4aa69cf47dd8bc43c_JaffaCakes118

  • Size

    127KB

  • Sample

    240605-zhb7aahh57

  • MD5

    993333c113dec2b4aa69cf47dd8bc43c

  • SHA1

    bf920b350983308cb8cb8827a8056c7fdb7d9c63

  • SHA256

    cdaeb08ef95a325e8f0ef202ca811212aba8fc96a6c6a1dcbaa57c9057d79dab

  • SHA512

    c48731ef1ce680936fcccac2624d6dfff8a271f536a3a6f56b1dd1b79bd8c4ba6dfe1e2bdc89696edde4283f927c93c88a430840364927be9be882339a67e359

  • SSDEEP

    3072:Uq3E2BfBSbEsz7nCAFVNNvBGvdO5gPaEjep8Fe7Z1iO7ZbvbeV7:BRBfBSosz7nCA3NHCdXaEj7Fe7Z1iOF

Malware Config

Extracted

Family

netwire

C2

extreme33.dns1.us:33400

Attributes
  • activex_autorun

    false

  • copy_executable

    false

  • delete_original

    false

  • host_id

    HostId-%Rand%

  • keylogger_dir

    %AppData%\Logs\

  • lock_executable

    false

  • mutex

    QKgXfnNw

  • offline_keylogger

    true

  • password

    Password

  • registry_autorun

    false

  • use_mutex

    true

Targets

    • Target

      993333c113dec2b4aa69cf47dd8bc43c_JaffaCakes118

    • Size

      127KB

    • MD5

      993333c113dec2b4aa69cf47dd8bc43c

    • SHA1

      bf920b350983308cb8cb8827a8056c7fdb7d9c63

    • SHA256

      cdaeb08ef95a325e8f0ef202ca811212aba8fc96a6c6a1dcbaa57c9057d79dab

    • SHA512

      c48731ef1ce680936fcccac2624d6dfff8a271f536a3a6f56b1dd1b79bd8c4ba6dfe1e2bdc89696edde4283f927c93c88a430840364927be9be882339a67e359

    • SSDEEP

      3072:Uq3E2BfBSbEsz7nCAFVNNvBGvdO5gPaEjep8Fe7Z1iO7ZbvbeV7:BRBfBSosz7nCA3NHCdXaEj7Fe7Z1iOF

    • NetWire RAT payload

    • Netwire

      Netwire is a RAT with main functionalities focused password stealing and keylogging, but also includes remote control capabilities as well.

MITRE ATT&CK Matrix

Tasks