General

  • Target

    9e96b0ca6af610467e378ce574c46ac8_JaffaCakes118

  • Size

    336KB

  • Sample

    240611-sebm1s1gqr

  • MD5

    9e96b0ca6af610467e378ce574c46ac8

  • SHA1

    f0b6b0ba3b3837ea5045ddc67aca09b30929ba25

  • SHA256

    d1a50d7dff2d6e797a91bb21476340b6b6f38149602e78e8c67285e629ab5582

  • SHA512

    f371a472d328d0c09a714ff4002fed0f85d75971c187f1418adb2524c5787635dccd1b5dba810fe3806ad587bf5030934809777463636ba4792d511787590ee9

  • SSDEEP

    6144:KLRglTOTgZB2LmLqMTU5KJMQPesmX/YmRMW:KLRdTxauMsKaQPtmAmRM

Malware Config

Extracted

Family

formbook

Version

3.8

Campaign

he

Decoy

wwws8884.com

kingofcat.com

tv17890.info

mayohomes.properties

digitaltaj.com

5x000.com

guoguoxiansen.com

712manbetx.com

subastacalicar.com

online-rueckbildung.com

cruisekaribu.com

chaomojia.com

dropmefile.info

cellcity.photography

gmckeeptexasrolling.net

peoplesinc.biz

pi3kinbreastcancer.com

kudstaxi.com

xhtd842.com

saverioscattaglia.com

Targets

    • Target

      9e96b0ca6af610467e378ce574c46ac8_JaffaCakes118

    • Size

      336KB

    • MD5

      9e96b0ca6af610467e378ce574c46ac8

    • SHA1

      f0b6b0ba3b3837ea5045ddc67aca09b30929ba25

    • SHA256

      d1a50d7dff2d6e797a91bb21476340b6b6f38149602e78e8c67285e629ab5582

    • SHA512

      f371a472d328d0c09a714ff4002fed0f85d75971c187f1418adb2524c5787635dccd1b5dba810fe3806ad587bf5030934809777463636ba4792d511787590ee9

    • SSDEEP

      6144:KLRglTOTgZB2LmLqMTU5KJMQPesmX/YmRMW:KLRdTxauMsKaQPtmAmRM

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Scheduled Task/Job

1
T1053

Privilege Escalation

Scheduled Task/Job

1
T1053

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks