General
-
Target
a51b305d46ffaf99c0e22947ca9dab99_JaffaCakes118
-
Size
171KB
-
Sample
240613-mm42msygnm
-
MD5
a51b305d46ffaf99c0e22947ca9dab99
-
SHA1
4c849d8cb31064a4cf8662b7ca928f9d6400f212
-
SHA256
6f4fbebfa1e80ede53f52fa98f180fc3ad9938504b7824dbf5e1a3d69f722f4d
-
SHA512
641a7b897ef456a423b91c307ae8a091c9b183fa94bc3a2e3015e33405f548f4894704ab2466c10ac8d8b399bc59a51ca771ba4b1420bcef6264e84e3f43e3d5
-
SSDEEP
3072:K2lyjP4+eFt7A+xGLHLllRAuSme2d57c3NFTiPCr5nT4eE8tdIvso0Pm7U04P2Y6:KwyE+eFtKllRrXMOTaTXPm7U04+YIOo
Static task
static1
Behavioral task
behavioral1
Sample
usd23000scandoc.pdf.exe
Resource
win7-20240611-en
Malware Config
Extracted
formbook
3.8
mx40
vr-edu.group
mangobajo.com
390hash.com
coin-project.com
haninmax.com
ephotgraphyonline.info
gini.ltd
occurri.info
retireviainternet.com
thegoodkindacrazy.com
colebrookwines.com
fermartinezphotography.com
taurustal.com
lage.ltd
opportunisticnomnomivore.com
eoc-org.com
soinsdentaires-etranger.com
americanas-aniversario.com
weixindaochu.com
aliancabrindes.com
vbuhler.com
designsbydanyale.com
156beckwithavenue.com
takahashimiho.com
adkintl.com
humanitysharmonics.com
inquiry.company
isabellepoche.com
buymyrihouse.com
modabellezayhogar.com
wzydb.net
equifaxsecurity2017f.com
wajueshuju.com
nokohan.com
toru.ltd
jacuzzihottubsofirvine.com
hhjinyangguang.com
zhuoanvip.com
majorcrane.com
rcmco.info
saoav70701.com
thebluewatergroupinc.com
wartapuskesmas.com
energyeecd.party
bltgo.info
healthymealrecipes.net
oasisproductions.info
uzdxs.com
meenababu.com
grindcoreshop.com
sdbhgy7.ink
ihaztwojayz.com
felsrl.info
xpresspodhub.com
squarelump.com
hpxsupport.com
cienciasdelsuelo.com
lebistrotdutrolley.com
believers.graphics
smyeoforum.win
naturalpathmd.com
wpstairs.com
weizan.site
onaalandaclubmarbella.com
beemptty.com
Targets
-
-
Target
usd23000scandoc.pdf.exe
-
Size
184KB
-
MD5
5f38331663118f710642957241c9238d
-
SHA1
04781426ede2fa8852f25ed2da5594db74783773
-
SHA256
ec4d14568d4e11d2f5a78f752eaaf3770eaf939d192affd7ef935e418f632024
-
SHA512
c0e8dbdd14f1963f41de266b58f427a83d80636ddf7c11bcbb8cb1a49fabf0b402b0895ba4f5328960a174bfcc11a75016bbc5c7588e2d7d1eb03e6297fcdd1e
-
SSDEEP
3072:SyvIcfKQjH4ULQtYyhEgHqjex7ob2TU5Nb8yW2vqwxmr7DQ03LiTIpe+HJeUlp:Sywc9DLQtYyhcjf6WGyFfC7DQcow
-
Formbook payload
-
Deletes itself
-
Suspicious use of SetThreadContext
-