General

  • Target

    ae816597f9990952c8b6f523b64f24c9_JaffaCakes118

  • Size

    1008KB

  • Sample

    240615-p273ys1dpf

  • MD5

    ae816597f9990952c8b6f523b64f24c9

  • SHA1

    f6a8209eebb95669f4c1223d4abe02888bf54173

  • SHA256

    98605f399585016ae41edcfbc496fa98225ad51928b26b9dff6261fbc09d7d7f

  • SHA512

    0847a636793b165dc30e3269ecda30371d26700ab213f34432912662f32431d1be1a6c811184a68aa6b3455ba392285524e7366695b3db642cc7f897da03c0bc

  • SSDEEP

    12288:jcZsEIkKatBE0nv8Po4GxxlZsEIkKatBE0nv8Po4Gxx1ko:AZZIkbBTEQ4UZZIkbBTEQ4Po

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

k8b

Decoy

happycampersevents.com

sdjlhbsbgc.com

stephenkapere.com

iammelissamay.com

westhillsterracepdx.com

exceptionalhospitals.com

newnongye.com

sfheli.com

ytalmorales.com

etkensigorta.com

trophemus-treasure-hunters.com

ppcreselleraccount.com

prelovedfashiontreasures.com

santrixpharma.com

ahwxshop.com

7sat.asia

pitadippers.com

citestaccnt1598634983.com

testcaresort.com

supportcorder.com

Targets

    • Target

      ae816597f9990952c8b6f523b64f24c9_JaffaCakes118

    • Size

      1008KB

    • MD5

      ae816597f9990952c8b6f523b64f24c9

    • SHA1

      f6a8209eebb95669f4c1223d4abe02888bf54173

    • SHA256

      98605f399585016ae41edcfbc496fa98225ad51928b26b9dff6261fbc09d7d7f

    • SHA512

      0847a636793b165dc30e3269ecda30371d26700ab213f34432912662f32431d1be1a6c811184a68aa6b3455ba392285524e7366695b3db642cc7f897da03c0bc

    • SSDEEP

      12288:jcZsEIkKatBE0nv8Po4GxxlZsEIkKatBE0nv8Po4Gxx1ko:AZZIkbBTEQ4UZZIkbBTEQ4Po

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Scheduled Task/Job

1
T1053

Privilege Escalation

Scheduled Task/Job

1
T1053

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks