General

  • Target

    bbaaca3df24ceb257d22854cac390f46_JaffaCakes118

  • Size

    973KB

  • Sample

    240618-ngr1kavhpm

  • MD5

    bbaaca3df24ceb257d22854cac390f46

  • SHA1

    42eabeb3ee7475b1a68babe2aa96118c6c3e6e1e

  • SHA256

    5c7e88f3840237ba479019cc2c86421db7f695c13dfeffe7f2db121158e42d81

  • SHA512

    abc5b31f99bd39862fa6adad60191bcb26f9fcfd72c12bb67dca62dc6064858ee67b4bc8498a2eaf629a820bb2528d0a8a534c3a2375735008c5c4f4223e041e

  • SSDEEP

    24576:s4zQaPkDpZdKUUyUn6HaNpKwD0gpV6HwR:J

Malware Config

Extracted

Family

formbook

Version

3.8

Campaign

xa

Decoy

laplayaencantada.net

francesemartin.biz

mydailyadverts.biz

themansiononwalnut.com

kccoin.net

lighthousenw.net

ideadubai.com

coat.ink

happiestmarriage101.com

god16.com

datecleanse.com

559453.top

nagwarerecords.com

xn--husw9zrks.com

welfarereform.net

grupocastedia.com

aqua-armor.online

hopugo.com

mylovesociety.com

exploremusicjax.com

Targets

    • Target

      bbaaca3df24ceb257d22854cac390f46_JaffaCakes118

    • Size

      973KB

    • MD5

      bbaaca3df24ceb257d22854cac390f46

    • SHA1

      42eabeb3ee7475b1a68babe2aa96118c6c3e6e1e

    • SHA256

      5c7e88f3840237ba479019cc2c86421db7f695c13dfeffe7f2db121158e42d81

    • SHA512

      abc5b31f99bd39862fa6adad60191bcb26f9fcfd72c12bb67dca62dc6064858ee67b4bc8498a2eaf629a820bb2528d0a8a534c3a2375735008c5c4f4223e041e

    • SSDEEP

      24576:s4zQaPkDpZdKUUyUn6HaNpKwD0gpV6HwR:J

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Process spawned unexpected child process

      This typically indicates the parent process was compromised via an exploit or macro.

    • Formbook payload

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks