General

  • Target

    1ad2aa64e212a330fbc273202aa820b7_JaffaCakes118

  • Size

    252KB

  • Sample

    240701-lsa53sxhjl

  • MD5

    1ad2aa64e212a330fbc273202aa820b7

  • SHA1

    d10ebfe679731804aaafc0f201e4c85cde2d38c2

  • SHA256

    05b799658437233cbe4c86b17c6565ee9997c390b199cfd77fdfa673e084cb6b

  • SHA512

    41c7b35827d4cca85386766ceaed0ce1510ca9a0b34cfbbdf6a7e66d3e28d820a4d3d38f3071cfe7e078eb6182084bd3f86939ea03b82a3bfe8f022fead25998

  • SSDEEP

    6144:91OgDPdkBAFZWjadD4so5o7oCMw8G29TUs:91OgLdajrnbVL

Malware Config

Targets

    • Target

      1ad2aa64e212a330fbc273202aa820b7_JaffaCakes118

    • Size

      252KB

    • MD5

      1ad2aa64e212a330fbc273202aa820b7

    • SHA1

      d10ebfe679731804aaafc0f201e4c85cde2d38c2

    • SHA256

      05b799658437233cbe4c86b17c6565ee9997c390b199cfd77fdfa673e084cb6b

    • SHA512

      41c7b35827d4cca85386766ceaed0ce1510ca9a0b34cfbbdf6a7e66d3e28d820a4d3d38f3071cfe7e078eb6182084bd3f86939ea03b82a3bfe8f022fead25998

    • SSDEEP

      6144:91OgDPdkBAFZWjadD4so5o7oCMw8G29TUs:91OgLdajrnbVL

    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Browser Extensions

1
T1176

Defense Evasion

Modify Registry

2
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

1
T1005

Tasks