General

  • Target

    136cd3003a8ca3ad6c454a4bfce0525f_JaffaCakes118

  • Size

    637KB

  • Sample

    240626-zrvd8awdnp

  • MD5

    136cd3003a8ca3ad6c454a4bfce0525f

  • SHA1

    bea4e7267de00e10524b0d06de24abdd527188f9

  • SHA256

    184f46651603fccccbba6ab8283a1551c8b41213e1b2522493e4b309e5ffcf56

  • SHA512

    d4d3d99d34a0e9a10c27d7c6e519b19218eee29d13fe274243351e4636d1aa8a0efb12266ab0d079d4cbcfa1dbfd3315b8f4e305b2774d133daf4f5798aad248

  • SSDEEP

    12288:6fnbQ+X8+UiDLbRHahW0gZvL7zbRAJEc2vLYitEUspMif+q3eCEAxa+n1pw:cbQ+X8+UiDLbRHahWDZ3Hc2vvWM0+SeE

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

bkye

Decoy

lawnandgardenzone.com

eazymoneyindia.com

macroscopicsystem.com

aocsw.com

maisonetjardinltd.com

khadijahtv.com

shashameneland.com

kildebasen.com

lovetxts.com

easycompanyarmory.com

surviveit.info

greenterra.solutions

ushergiving.com

stickyickybakery.com

pyesquard.com

dailyinformerblog.com

thekimchilife.com

rainbow-bm.com

bosonetwork.com

bestacnetreatmentever.com

Targets

    • Target

      136cd3003a8ca3ad6c454a4bfce0525f_JaffaCakes118

    • Size

      637KB

    • MD5

      136cd3003a8ca3ad6c454a4bfce0525f

    • SHA1

      bea4e7267de00e10524b0d06de24abdd527188f9

    • SHA256

      184f46651603fccccbba6ab8283a1551c8b41213e1b2522493e4b309e5ffcf56

    • SHA512

      d4d3d99d34a0e9a10c27d7c6e519b19218eee29d13fe274243351e4636d1aa8a0efb12266ab0d079d4cbcfa1dbfd3315b8f4e305b2774d133daf4f5798aad248

    • SSDEEP

      12288:6fnbQ+X8+UiDLbRHahW0gZvL7zbRAJEc2vLYitEUspMif+q3eCEAxa+n1pw:cbQ+X8+UiDLbRHahWDZ3Hc2vvWM0+SeE

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks