General

  • Target

    b90130e8fd69765e43e2c8cbebb853d0_JaffaCakes118

  • Size

    550KB

  • Sample

    240617-vhn4mawfka

  • MD5

    b90130e8fd69765e43e2c8cbebb853d0

  • SHA1

    9bae58558ba71dccd2ad6ff8ac0621bdbe2af862

  • SHA256

    7148ce6420b6f8c7c6f04ab4c8097304cc88e658a686676018b0a104ebc0e2b4

  • SHA512

    6fac1441fb9d327797c305b37971365c93c457b43563724c990f270ed05c1b04b3716293af1549ce3957030c16ae1f90c9f30d0201cbac4ec4677f2d15451499

  • SSDEEP

    12288:w6eqOdDePE45wOcK3NXW81l4VNrMMTiBUf4r:w5qE4N1X1lxMWY4r

Malware Config

Extracted

Family

raccoon

Botnet

f3f30b743bf115afe6867952697df52ae13a1288

Attributes
  • url4cnc

    https://drive.google.com/uc?export=download&id=1gPJW2MkGFrAsZnPIQ6T6xVSU9pSdV8ZN

rc4.plain
rc4.plain

Targets

    • Target

      b90130e8fd69765e43e2c8cbebb853d0_JaffaCakes118

    • Size

      550KB

    • MD5

      b90130e8fd69765e43e2c8cbebb853d0

    • SHA1

      9bae58558ba71dccd2ad6ff8ac0621bdbe2af862

    • SHA256

      7148ce6420b6f8c7c6f04ab4c8097304cc88e658a686676018b0a104ebc0e2b4

    • SHA512

      6fac1441fb9d327797c305b37971365c93c457b43563724c990f270ed05c1b04b3716293af1549ce3957030c16ae1f90c9f30d0201cbac4ec4677f2d15451499

    • SSDEEP

      12288:w6eqOdDePE45wOcK3NXW81l4VNrMMTiBUf4r:w5qE4N1X1lxMWY4r

    • Raccoon

      Raccoon is an infostealer written in C++ and first seen in 2019.

    • Raccoon Stealer V1 payload

    • Legitimate hosting services abused for malware hosting/C2

MITRE ATT&CK Matrix ATT&CK v13

Tasks