General

  • Target

    19ab998678cac958a77b56a184542ef4_JaffaCakes118

  • Size

    373KB

  • Sample

    240628-lqgvvawakr

  • MD5

    19ab998678cac958a77b56a184542ef4

  • SHA1

    f276e754de9070cceb49f8156d2cca3d6d6234f8

  • SHA256

    559ff87a36f3da860eed67fa41844d1d73cdfbba466d8dd7c9664be3698d8e5c

  • SHA512

    e3c1438e39a4157625d4c3cee34c9f6ac2f97f57798c0c03c1b301204872d17fcdb8f45de7d785e8e60a65f927cab63f3f240e644875e42b823fd4ddd5429335

  • SSDEEP

    6144:Ch7BFTjgLcD6Pse5CqubrFzNl12SnClijtLgqJL6+OOhxxdeTr/ekI:CSgD63M5/FzIhijtBL68zxd6L

Malware Config

Extracted

Family

gcleaner

C2

gcl-page.biz

194.145.227.161

Targets

    • Target

      19ab998678cac958a77b56a184542ef4_JaffaCakes118

    • Size

      373KB

    • MD5

      19ab998678cac958a77b56a184542ef4

    • SHA1

      f276e754de9070cceb49f8156d2cca3d6d6234f8

    • SHA256

      559ff87a36f3da860eed67fa41844d1d73cdfbba466d8dd7c9664be3698d8e5c

    • SHA512

      e3c1438e39a4157625d4c3cee34c9f6ac2f97f57798c0c03c1b301204872d17fcdb8f45de7d785e8e60a65f927cab63f3f240e644875e42b823fd4ddd5429335

    • SSDEEP

      6144:Ch7BFTjgLcD6Pse5CqubrFzNl12SnClijtLgqJL6+OOhxxdeTr/ekI:CSgD63M5/FzIhijtBL68zxd6L

    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • OnlyLogger

      A tiny loader that uses IPLogger to get its payload.

    • OnlyLogger payload

MITRE ATT&CK Matrix

Tasks