General

  • Target

    021cdb850fe09593d45b048ae3196acc_JaffaCakes118

  • Size

    655KB

  • Sample

    240620-c5vwksthne

  • MD5

    021cdb850fe09593d45b048ae3196acc

  • SHA1

    b591a65f0957b17f975def85b65f7e50f89768d3

  • SHA256

    87b06830e0b34bdf03603b903ab48c890582bf47bc8cc1704206159d951834e2

  • SHA512

    465063897c25616e33a4853eed628fa5e7cb7b0e4ccdfae9d2aa64665d03d2409ec6b4954e2c21c3454dba889cc254d66867c329a45078ef1beb3891ff5d1571

  • SSDEEP

    12288:g9DN9uW1XeqFYDeA/pSuk7fMo5Td5DUhj/5clKKQ17NiPcc4h9YX0:ghvuW19juzKlKKG7kPUV

Malware Config

Extracted

Family

gozi

Targets

    • Target

      021cdb850fe09593d45b048ae3196acc_JaffaCakes118

    • Size

      655KB

    • MD5

      021cdb850fe09593d45b048ae3196acc

    • SHA1

      b591a65f0957b17f975def85b65f7e50f89768d3

    • SHA256

      87b06830e0b34bdf03603b903ab48c890582bf47bc8cc1704206159d951834e2

    • SHA512

      465063897c25616e33a4853eed628fa5e7cb7b0e4ccdfae9d2aa64665d03d2409ec6b4954e2c21c3454dba889cc254d66867c329a45078ef1beb3891ff5d1571

    • SSDEEP

      12288:g9DN9uW1XeqFYDeA/pSuk7fMo5Td5DUhj/5clKKQ17NiPcc4h9YX0:ghvuW19juzKlKKG7kPUV

    • Gozi

      Gozi is a well-known and widely distributed banking trojan.

    • Executes dropped EXE

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

Tasks