General

  • Target

    9391d438c1ed4ec480a9deade12e6c5bd8d4b68150934aef2108b1fcd5a9df51

  • Size

    3.8MB

  • Sample

    240630-bwvc1s1hjd

  • MD5

    15e2f2b87b8a8aed853b4cfc846def7f

  • SHA1

    0cdac8f2a2741ce54c5af62de51e6bdc7253f7db

  • SHA256

    9391d438c1ed4ec480a9deade12e6c5bd8d4b68150934aef2108b1fcd5a9df51

  • SHA512

    4009e9692a6f1190a2724d9d0de7debfd50c95ff7eb7e8ecc293097205e8a07f64c01fd890165fd2317ec48a0677f1d6c2c3552ad3dabdaef7a98c33b7c36816

  • SSDEEP

    49152:mppLcWwqjMbMOJSElmSbFjW5ElYBjhuCPiVcFD64WWBru1QE7FfRN6kLdz:0HhySElmSbeElgvNDN9BCpFJNJL

Malware Config

Extracted

Family

cobaltstrike

C2

http://1.13.182.17:8443/jquery-3.3.2.slim.min.js

Attributes
  • user_agent

    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Referer: http://code.jquery.com/ Accept-Encoding: gzip, deflate User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko

Targets

    • Target

      9391d438c1ed4ec480a9deade12e6c5bd8d4b68150934aef2108b1fcd5a9df51

    • Size

      3.8MB

    • MD5

      15e2f2b87b8a8aed853b4cfc846def7f

    • SHA1

      0cdac8f2a2741ce54c5af62de51e6bdc7253f7db

    • SHA256

      9391d438c1ed4ec480a9deade12e6c5bd8d4b68150934aef2108b1fcd5a9df51

    • SHA512

      4009e9692a6f1190a2724d9d0de7debfd50c95ff7eb7e8ecc293097205e8a07f64c01fd890165fd2317ec48a0677f1d6c2c3552ad3dabdaef7a98c33b7c36816

    • SSDEEP

      49152:mppLcWwqjMbMOJSElmSbFjW5ElYBjhuCPiVcFD64WWBru1QE7FfRN6kLdz:0HhySElmSbeElgvNDN9BCpFJNJL

MITRE ATT&CK Matrix

Tasks