General
-
Target
0ae1d575dea5e89a50020dcbac89bc85_JaffaCakes118
-
Size
379KB
-
Sample
240624-127mzavaqd
-
MD5
0ae1d575dea5e89a50020dcbac89bc85
-
SHA1
64fbe90c0f4682c877d736bd4212b640d9c73992
-
SHA256
e71411a441adaeb572af1b3e9c9a28616bc952ad94def8b4da216d38dd6fee6a
-
SHA512
6ef5fcd51d4191752bfe0a3774b7f197f7832fa7195b072b259ea0a1b7bf790169738a62a2aea5c816a96c5ce6a39df8f0c7982ff1143c10826a042f995ba1fb
-
SSDEEP
6144:mjEzuP3R3EEuQD/ydTpGyC+tV0js+hU6sPx/QgR7W0mUMtPEGgEAWajLNCmnxvFz:nuP3MQDKJpSj45UMjVjwmwaUkj
Static task
static1
Behavioral task
behavioral1
Sample
invoice copypdf.exe
Resource
win7-20240221-en
Malware Config
Extracted
formbook
4.1
mnf
freeedomfencemn.com
corse-pollens.com
gellyc.com
mindplusgrind.com
gzrikang.com
horukac.com
aswaqina.com
lawofficeofjimhankey.com
everyoneshoroscope.com
freisaq.com
khimyoga.com
usmarketingdigital.com
artistagospel.com
stop-moskitos.com
sertecbasicos.com
mvmontessori.net
duke-a-website.com
arcaneunlocked.com
turnershydrographics.com
bipbopbling.com
bailey-grey-sage.com
laplatesforme.com
resistrebel.com
adskliq.com
riyapalace.com
hxdhn.net
kentbranding.company
peninsulamatchmakers.net
haarausfall-info.com
artesanatosincero.com
unboundpublish.tech
zhongtangwealth.com
seoultechpe.com
antimohg.com
geniuslims.com
usacarkit.com
thegenvalue.com
soulpainting.vision
chituma2004.com
enjoybespokenwords.com
movetolancaster.com
igmasteryclub.com
imtheonlyperson.com
playerucas.com
service-9902.com
youronlinewholesaler.com
goodjob.ink
bdypss.com
icpropertiesllc.com
baove.info
brokerltsas.com
vikegame.info
aventurahdrealty.com
neurologistaandreialamberti.com
goatfare.com
funservicesflorida.com
infinitehandyman.net
alhemmah-store.com
janasfuncakes.com
sekolahsukses.com
ooc.xyz
gohawthorne.com
spotr.net
420cardsaz.com
jerkerings.com
Targets
-
-
Target
invoice copypdf.exe
-
Size
408KB
-
MD5
d9ae02ae949ec2aba95cda647fe09240
-
SHA1
3858a6e45d0031fcbd9081dee453fdf196cc95a4
-
SHA256
75a0f38d45e726a70992f82304bfb85b127c37e591c02c59fe5750d308a95bd6
-
SHA512
f724c3ab608fdd6393147a2534d035b2211848efc091bcf73fb20ef2476a1705df9a423ccfe732903b8ed4fd6bef1d361e9881d5c767089ae2f5377049c97a46
-
SSDEEP
12288:KnzmVzil201tDwa2rGcLSY5ndlqChvqeA:KnzmVzK5S0cLSY5ndlqov
-
Formbook payload
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Deletes itself
-
Suspicious use of SetThreadContext
-