General

  • Target

    1a96dd845c1b56f76f73181346ada244_JaffaCakes118

  • Size

    313KB

  • Sample

    240701-kaxqpavcjp

  • MD5

    1a96dd845c1b56f76f73181346ada244

  • SHA1

    db1cd021cc5193c424aa743beb1377ce289acdd3

  • SHA256

    06a3d63d7af77a0fc0c13d3e35877b6b37425d9e8b328c9d45107d324be37b6f

  • SHA512

    06213edf28d97ee6ce5fb22bf72902e729d49c821aaa2f0130c192db7daec12f10d40c18a9408ea01139b172d28721382515a8758376014f85e38eb7ec9f536f

  • SSDEEP

    6144:91OgDPdkBAFZWjadD4snWO7jI+cGD54kHX8ZtvuB6d+h2kO:91OgLdaGHI6D5jHB2+hZO

Malware Config

Targets

    • Target

      1a96dd845c1b56f76f73181346ada244_JaffaCakes118

    • Size

      313KB

    • MD5

      1a96dd845c1b56f76f73181346ada244

    • SHA1

      db1cd021cc5193c424aa743beb1377ce289acdd3

    • SHA256

      06a3d63d7af77a0fc0c13d3e35877b6b37425d9e8b328c9d45107d324be37b6f

    • SHA512

      06213edf28d97ee6ce5fb22bf72902e729d49c821aaa2f0130c192db7daec12f10d40c18a9408ea01139b172d28721382515a8758376014f85e38eb7ec9f536f

    • SSDEEP

      6144:91OgDPdkBAFZWjadD4snWO7jI+cGD54kHX8ZtvuB6d+h2kO:91OgLdaGHI6D5jHB2+hZO

    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Browser Extensions

1
T1176

Defense Evasion

Modify Registry

2
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

1
T1005

Tasks