General

  • Target

    41cf2b41d2526e97053029cff9a7477c675c488c3bbc8678f517a3f8f197ae03

  • Size

    24KB

  • Sample

    240628-melv4athlg

  • MD5

    c2f828300819b501ef6cd1e2501e998c

  • SHA1

    a69a28caa9f39827e98b35953d26846c73e6ddcf

  • SHA256

    41cf2b41d2526e97053029cff9a7477c675c488c3bbc8678f517a3f8f197ae03

  • SHA512

    be76e1ff1f40ca052842498bcdf4f852c1a32e3d2e87d9bd81b9ed9328303db03cf71cc183085e6e8b9d8acc4307b7d1f5b67251cb6b28f5f4d953e73b69e2e1

  • SSDEEP

    384:WdCbf/MIERPrUMe7k5N6utayNBnwhveQvz6HANi:H6tayT2POHY

Malware Config

Extracted

Family

cobaltstrike

C2

http://89.117.94.85:4326/jquery-3.3.2.slim.min.js

Attributes
  • user_agent

    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Referer: http://code.jquery.com/ Accept-Encoding: gzip, deflate User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko

Targets

    • Target

      41cf2b41d2526e97053029cff9a7477c675c488c3bbc8678f517a3f8f197ae03

    • Size

      24KB

    • MD5

      c2f828300819b501ef6cd1e2501e998c

    • SHA1

      a69a28caa9f39827e98b35953d26846c73e6ddcf

    • SHA256

      41cf2b41d2526e97053029cff9a7477c675c488c3bbc8678f517a3f8f197ae03

    • SHA512

      be76e1ff1f40ca052842498bcdf4f852c1a32e3d2e87d9bd81b9ed9328303db03cf71cc183085e6e8b9d8acc4307b7d1f5b67251cb6b28f5f4d953e73b69e2e1

    • SSDEEP

      384:WdCbf/MIERPrUMe7k5N6utayNBnwhveQvz6HANi:H6tayT2POHY

MITRE ATT&CK Matrix

Tasks