General

  • Target

    0ae1d575dea5e89a50020dcbac89bc85_JaffaCakes118

  • Size

    379KB

  • Sample

    240624-127mzavaqd

  • MD5

    0ae1d575dea5e89a50020dcbac89bc85

  • SHA1

    64fbe90c0f4682c877d736bd4212b640d9c73992

  • SHA256

    e71411a441adaeb572af1b3e9c9a28616bc952ad94def8b4da216d38dd6fee6a

  • SHA512

    6ef5fcd51d4191752bfe0a3774b7f197f7832fa7195b072b259ea0a1b7bf790169738a62a2aea5c816a96c5ce6a39df8f0c7982ff1143c10826a042f995ba1fb

  • SSDEEP

    6144:mjEzuP3R3EEuQD/ydTpGyC+tV0js+hU6sPx/QgR7W0mUMtPEGgEAWajLNCmnxvFz:nuP3MQDKJpSj45UMjVjwmwaUkj

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

mnf

Decoy

freeedomfencemn.com

corse-pollens.com

gellyc.com

mindplusgrind.com

gzrikang.com

horukac.com

aswaqina.com

lawofficeofjimhankey.com

everyoneshoroscope.com

freisaq.com

khimyoga.com

usmarketingdigital.com

artistagospel.com

stop-moskitos.com

sertecbasicos.com

mvmontessori.net

duke-a-website.com

arcaneunlocked.com

turnershydrographics.com

bipbopbling.com

Targets

    • Target

      invoice copypdf.exe

    • Size

      408KB

    • MD5

      d9ae02ae949ec2aba95cda647fe09240

    • SHA1

      3858a6e45d0031fcbd9081dee453fdf196cc95a4

    • SHA256

      75a0f38d45e726a70992f82304bfb85b127c37e591c02c59fe5750d308a95bd6

    • SHA512

      f724c3ab608fdd6393147a2534d035b2211848efc091bcf73fb20ef2476a1705df9a423ccfe732903b8ed4fd6bef1d361e9881d5c767089ae2f5377049c97a46

    • SSDEEP

      12288:KnzmVzil201tDwa2rGcLSY5ndlqChvqeA:KnzmVzK5S0cLSY5ndlqov

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks