General

  • Target

    15f120a8b26e0a0e82cf23c8b98f7b20_JaffaCakes118

  • Size

    72KB

  • Sample

    240627-n9t1masgqn

  • MD5

    15f120a8b26e0a0e82cf23c8b98f7b20

  • SHA1

    fc535b515a1483a3afd238d800c7e8f4a1163356

  • SHA256

    db0d9b4eb0d108b9dae9b84df063b1ab42355a117ee4c0cf6a8a3c828dc48321

  • SHA512

    d121402488a89182f92a2dfc36fac41a444970916b4e99892fa3d8425b5d25af8658399db9df9b541534343530ed15026a994f28ab55e40140782f778e2c2e5d

  • SSDEEP

    1536:Izw8NxX1G61gj23TjrIOsznXMb+KR0Nc8QsJq39:Wwyv1737IXbe0Nc8QsC9

Malware Config

Extracted

Family

metasploit

Version

windows/shell_reverse_tcp

C2

192.168.174.200:4444

Targets

    • Target

      15f120a8b26e0a0e82cf23c8b98f7b20_JaffaCakes118

    • Size

      72KB

    • MD5

      15f120a8b26e0a0e82cf23c8b98f7b20

    • SHA1

      fc535b515a1483a3afd238d800c7e8f4a1163356

    • SHA256

      db0d9b4eb0d108b9dae9b84df063b1ab42355a117ee4c0cf6a8a3c828dc48321

    • SHA512

      d121402488a89182f92a2dfc36fac41a444970916b4e99892fa3d8425b5d25af8658399db9df9b541534343530ed15026a994f28ab55e40140782f778e2c2e5d

    • SSDEEP

      1536:Izw8NxX1G61gj23TjrIOsznXMb+KR0Nc8QsJq39:Wwyv1737IXbe0Nc8QsC9

    • MetaSploit

      Detected malicious payload which is part of the Metasploit Framework, likely generated with msfvenom or similar.

MITRE ATT&CK Matrix

Tasks