General

  • Target

    14073747c219f890f793300d883dc11e_JaffaCakes118

  • Size

    1.9MB

  • Sample

    240627-ar22masemf

  • MD5

    14073747c219f890f793300d883dc11e

  • SHA1

    3f856d534481a0e21fd5ad78b6e704f43bb95429

  • SHA256

    10e6fe685ba524be5fc4bd0b868e72fd113b9529f8e3428d6c7736aeffe1ee02

  • SHA512

    f713b319b94c45182131ea5b27f7d1423468b95ee5f5616ee27f1ff253a9a2aef6e9ed47fec1416018dfaa6f74cd03f34022d09c4c4f985e839eded6f4ff4c90

  • SSDEEP

    24576:qy7Dbx6R8hJ4XF9zK9j+AM4SaDAVxXEEZ4UJKW1mYLFeCXDMDYOg7:lDxyF9Ca9Z4UJKW1mYLFeCXDMDYOg

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

gbr

Decoy

serabet.com

galanggroup.com

zweitmeinung-urologie.com

damsalon.com

binliwine.com

lifeladderindia.com

flyingwranchmanagement.com

tripsandturns.com

3headdesign.com

aluminumfacade.com

toprestau.com

facetreatspa.com

periodrescuekit.com

dbaojian.com

altinotokurtarma.com

gkpelle.com

loguslife.com

treatse.com

lghglzcnkx.net

jawharabh.com

Targets

    • Target

      14073747c219f890f793300d883dc11e_JaffaCakes118

    • Size

      1.9MB

    • MD5

      14073747c219f890f793300d883dc11e

    • SHA1

      3f856d534481a0e21fd5ad78b6e704f43bb95429

    • SHA256

      10e6fe685ba524be5fc4bd0b868e72fd113b9529f8e3428d6c7736aeffe1ee02

    • SHA512

      f713b319b94c45182131ea5b27f7d1423468b95ee5f5616ee27f1ff253a9a2aef6e9ed47fec1416018dfaa6f74cd03f34022d09c4c4f985e839eded6f4ff4c90

    • SSDEEP

      24576:qy7Dbx6R8hJ4XF9zK9j+AM4SaDAVxXEEZ4UJKW1mYLFeCXDMDYOg7:lDxyF9Ca9Z4UJKW1mYLFeCXDMDYOg

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks