General

  • Target

    150cc6fff4a7fca07ff09a3e37fb7828_JaffaCakes118

  • Size

    1.7MB

  • Sample

    240627-hm96fazelp

  • MD5

    150cc6fff4a7fca07ff09a3e37fb7828

  • SHA1

    0a77ae0762093dedebf497aae917c1bd29ec6407

  • SHA256

    f0f167b361376dc23b604f18e3642c459368c71e8e030e00170d5db431ceb45c

  • SHA512

    8246091ed11c659f7f8a3f5cf4df448d6632e62644662fddef29301f6ad82ba7c409682e238fec6bd07e95e17f5318b3351cb0e529b8b542ef126985bc070afd

  • SSDEEP

    49152:YmS7T6hb8lMKMDQzPFRUmN1lU5XUM8y+90O:C7TQb8+KbzPFRUm9U5kdP

Malware Config

Targets

    • Target

      150cc6fff4a7fca07ff09a3e37fb7828_JaffaCakes118

    • Size

      1.7MB

    • MD5

      150cc6fff4a7fca07ff09a3e37fb7828

    • SHA1

      0a77ae0762093dedebf497aae917c1bd29ec6407

    • SHA256

      f0f167b361376dc23b604f18e3642c459368c71e8e030e00170d5db431ceb45c

    • SHA512

      8246091ed11c659f7f8a3f5cf4df448d6632e62644662fddef29301f6ad82ba7c409682e238fec6bd07e95e17f5318b3351cb0e529b8b542ef126985bc070afd

    • SSDEEP

      49152:YmS7T6hb8lMKMDQzPFRUmN1lU5XUM8y+90O:C7TQb8+KbzPFRUm9U5kdP

    • CryptBot

      A C++ stealer distributed widely in bundle with other software.

    • CryptBot payload

    • Manipulates Digital Signatures

      Attackers can apply techniques such as changing the registry keys of authenticode & Cryptography to obtain their binary as valid.

    • Executes dropped EXE

    • Reads data files stored by FTP clients

      Tries to access configuration files associated with programs like FileZilla.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Adds Run key to start application

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Subvert Trust Controls

1
T1553

SIP and Trust Provider Hijacking

1
T1553.003

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

3
T1552

Credentials In Files

3
T1552.001

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Collection

Data from Local System

3
T1005

Tasks