General

  • Target

    9ca3d7aef969d1460d82b86833904dce_JaffaCakes118

  • Size

    504KB

  • Sample

    240611-caek4szgll

  • MD5

    9ca3d7aef969d1460d82b86833904dce

  • SHA1

    b75c443f46403adddc7feee11e95bb601eb42c2b

  • SHA256

    4e1c286566b574f31f091644bcac2d2aec378002a42ca039a34561947078483b

  • SHA512

    2da51ad40d9011df045e4a7f241b1b4ca9917f06bf6129222820b86525468a5ffbe56940eb06de869cc384a945cd3d5356dc3a7a6f4c86458c4688df93fcbb5b

  • SSDEEP

    12288:dWWNkAMw7hj8FLCCeVBVivogDiggszuRkRa6o:dWaMw7R8FwnipviJ6o

Malware Config

Extracted

Family

formbook

Version

3.9

Campaign

ej

Decoy

ratnik.online

qqqq5025.com

oliverschmidtleipzig.biz

wallet-service4.com

securityinformation.link

kuaitool.com

chuanyuemeili.com

jetluxurysedansok.live

xn--autodrne-93a.com

ipdzke.men

opebet489.com

defamey.com

switchbank.finance

bplti.info

habomilk.com

onlineprintersupport.info

kansashemporium.com

xnewmovie.info

yuvakarshan.com

camwrshh.com

Targets

    • Target

      9ca3d7aef969d1460d82b86833904dce_JaffaCakes118

    • Size

      504KB

    • MD5

      9ca3d7aef969d1460d82b86833904dce

    • SHA1

      b75c443f46403adddc7feee11e95bb601eb42c2b

    • SHA256

      4e1c286566b574f31f091644bcac2d2aec378002a42ca039a34561947078483b

    • SHA512

      2da51ad40d9011df045e4a7f241b1b4ca9917f06bf6129222820b86525468a5ffbe56940eb06de869cc384a945cd3d5356dc3a7a6f4c86458c4688df93fcbb5b

    • SSDEEP

      12288:dWWNkAMw7hj8FLCCeVBVivogDiggszuRkRa6o:dWaMw7R8FwnipviJ6o

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks