General

  • Target

    1911d2ee2c7b6de6169816e24380a5a6_JaffaCakes118

  • Size

    72KB

  • Sample

    240628-gykt9axfkq

  • MD5

    1911d2ee2c7b6de6169816e24380a5a6

  • SHA1

    5f21fbe862f3aceae702abdd092d2ad2be95767f

  • SHA256

    955d5a1acf538a3950bd35d3d9a7b6fd7c65ce05c2b57168d5fc3c9f1297588a

  • SHA512

    878ae4e72b662dbf4a7f10b347fe0af5fe6ee81dfe85c822dc67b993e575cb9fd7fb2fcb0f4db759e86f1269330fde6f49d8781b1529d9d8cf866725ea8615ee

  • SSDEEP

    1536:IH4FcsT4Gq1h0zZtwuxiOKgS47S3KMb+KR0Nc8QsJq3H:dcXGq1KzLTVSKe0Nc8QsCH

Malware Config

Extracted

Family

metasploit

Version

windows/shell_reverse_tcp

C2

192.168.1.110:443

Targets

    • Target

      1911d2ee2c7b6de6169816e24380a5a6_JaffaCakes118

    • Size

      72KB

    • MD5

      1911d2ee2c7b6de6169816e24380a5a6

    • SHA1

      5f21fbe862f3aceae702abdd092d2ad2be95767f

    • SHA256

      955d5a1acf538a3950bd35d3d9a7b6fd7c65ce05c2b57168d5fc3c9f1297588a

    • SHA512

      878ae4e72b662dbf4a7f10b347fe0af5fe6ee81dfe85c822dc67b993e575cb9fd7fb2fcb0f4db759e86f1269330fde6f49d8781b1529d9d8cf866725ea8615ee

    • SSDEEP

      1536:IH4FcsT4Gq1h0zZtwuxiOKgS47S3KMb+KR0Nc8QsJq3H:dcXGq1KzLTVSKe0Nc8QsCH

    • MetaSploit

      Detected malicious payload which is part of the Metasploit Framework, likely generated with msfvenom or similar.

MITRE ATT&CK Matrix

Tasks