General

  • Target

    07d7d77033a62a22394399083da2d67d_JaffaCakes118

  • Size

    184KB

  • Sample

    240624-l2ke4swgka

  • MD5

    07d7d77033a62a22394399083da2d67d

  • SHA1

    9610fbf0c6a626382eb4c1c005590e282ee6cda4

  • SHA256

    d063a25fa2ccda0c87178079726a800fc0b3d1abe304c3400621bad4e0482289

  • SHA512

    8d4a06951b83214e02597ebdf9811efcb38c2a7bb03774179630e9870d0ad70756d4c280f9a7a015a002e4427d1b529776e4efa2a73c2c90e57ec8322b1d33dd

  • SSDEEP

    3072:mA3kqXpPKnXkU64fT/O7fbpvcI2yuOssp5kSmrzWV4S5:mA3kjn0GL/O7lvcITYekSSiV

Malware Config

Extracted

Family

dridex

Botnet

22201

C2

207.148.81.119:443

185.157.82.209:8333

5.39.99.208:5412

rc4.plain
rc4.plain

Targets

    • Target

      07d7d77033a62a22394399083da2d67d_JaffaCakes118

    • Size

      184KB

    • MD5

      07d7d77033a62a22394399083da2d67d

    • SHA1

      9610fbf0c6a626382eb4c1c005590e282ee6cda4

    • SHA256

      d063a25fa2ccda0c87178079726a800fc0b3d1abe304c3400621bad4e0482289

    • SHA512

      8d4a06951b83214e02597ebdf9811efcb38c2a7bb03774179630e9870d0ad70756d4c280f9a7a015a002e4427d1b529776e4efa2a73c2c90e57ec8322b1d33dd

    • SSDEEP

      3072:mA3kqXpPKnXkU64fT/O7fbpvcI2yuOssp5kSmrzWV4S5:mA3kjn0GL/O7lvcITYekSSiV

    • Dridex

      Dridex(known as Bugat/Cridex) is a form of malware that specializes in stealing bank credentials.

    • Dridex Loader

      Detects Dridex both x86 and x64 loader in memory.

MITRE ATT&CK Matrix

Tasks