General

  • Target

    183a8b19a056c944237876bea31a697c_JaffaCakes118

  • Size

    942KB

  • Sample

    240628-bgyrwsveqq

  • MD5

    183a8b19a056c944237876bea31a697c

  • SHA1

    c11f5484af3e4d8e34c35a7b7363078b0f23e079

  • SHA256

    d153e8b542963a9c9ae3fa96421f2ec2c5779759d0a086f3545b7e9c91074476

  • SHA512

    29821c783a90ffbeca765cb50e178fa772acc78b22b23490e7329b8b406cd6184e65359a24c068b3ac30936410b1a7920ed393b08ee2bb9e34fd81604eed89b6

  • SSDEEP

    12288:GO4jeQ5jsruJH+ReJqvqfLRXwK4+HNONnvsyl9vai2K046Mnq0UnsO5lJkKzUvoc:XHBQLW10ergut8+VuRHPXWMj

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

rf3t

Decoy

palmettohomeswakulla.com

sorelleapparel.com

abouttohour.com

ogrownhemp.com

themontagnard.com

zarioch.space

lty712.info

ajdstone.com

600plusgymspa.com

schmitzland.com

luhuigw.com

mysafeplacetoinsure.com

barkpark.club

investigation-science.com

sermonartnotes.net

gorgeousflippinllc.com

smarttrendshop.com

markusjungfoto.com

glyzaelbol.info

thewiseowl.art

Targets

    • Target

      183a8b19a056c944237876bea31a697c_JaffaCakes118

    • Size

      942KB

    • MD5

      183a8b19a056c944237876bea31a697c

    • SHA1

      c11f5484af3e4d8e34c35a7b7363078b0f23e079

    • SHA256

      d153e8b542963a9c9ae3fa96421f2ec2c5779759d0a086f3545b7e9c91074476

    • SHA512

      29821c783a90ffbeca765cb50e178fa772acc78b22b23490e7329b8b406cd6184e65359a24c068b3ac30936410b1a7920ed393b08ee2bb9e34fd81604eed89b6

    • SSDEEP

      12288:GO4jeQ5jsruJH+ReJqvqfLRXwK4+HNONnvsyl9vai2K046Mnq0UnsO5lJkKzUvoc:XHBQLW10ergut8+VuRHPXWMj

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks