General

  • Target

    9a4ca29834afb05956baa6d43941fdd4_JaffaCakes118

  • Size

    512KB

  • Sample

    240610-adb82she88

  • MD5

    9a4ca29834afb05956baa6d43941fdd4

  • SHA1

    2ffceafd456c1697b6f93271a49936f0e809b076

  • SHA256

    158d4f21670da0bdc2551260287309dce6643058dfb50c021b8e81a86e82dad2

  • SHA512

    a3c50675f0959dfdd80d004bdf5db39469e206afcbea1f1f0a94bbb170b7baa63af8577f1c64a0acfab469e345d9288bdde1d349761064bbec1c0b0e6ae59449

  • SSDEEP

    6144:cRm3AUGMaF7L7UEY41IDb/iCWYWHohrUi7N9iN9sWkgXFgx9XNP85B671xBvekLR:cIwU87fB1eb/49IhQg9ZOgx9sBc

Malware Config

Extracted

Family

raccoon

Botnet

2777c69672b2f58e15c06863817c3a62cca542f2

Attributes
  • url4cnc

    https://telete.in/mvexaria

rc4.plain
rc4.plain

Targets

    • Target

      9a4ca29834afb05956baa6d43941fdd4_JaffaCakes118

    • Size

      512KB

    • MD5

      9a4ca29834afb05956baa6d43941fdd4

    • SHA1

      2ffceafd456c1697b6f93271a49936f0e809b076

    • SHA256

      158d4f21670da0bdc2551260287309dce6643058dfb50c021b8e81a86e82dad2

    • SHA512

      a3c50675f0959dfdd80d004bdf5db39469e206afcbea1f1f0a94bbb170b7baa63af8577f1c64a0acfab469e345d9288bdde1d349761064bbec1c0b0e6ae59449

    • SSDEEP

      6144:cRm3AUGMaF7L7UEY41IDb/iCWYWHohrUi7N9iN9sWkgXFgx9XNP85B671xBvekLR:cIwU87fB1eb/49IhQg9ZOgx9sBc

    • Raccoon

      Raccoon is an infostealer written in C++ and first seen in 2019.

    • Raccoon Stealer V1 payload

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Tasks