General

  • Target

    1b095ac58a05fa9b8bc145600d31a39d_JaffaCakes118

  • Size

    432KB

  • Sample

    240701-m3snjs1ckk

  • MD5

    1b095ac58a05fa9b8bc145600d31a39d

  • SHA1

    a42ef0dcd3652df620d04428c319e173b99ee61f

  • SHA256

    c05e660e8265aea306ad08f3b1d5909fd80418750c9bd7cf1fba9f7b5b4d9141

  • SHA512

    a6092b8280e5cae2902d718b03bb7f05d8f1e349f18560e76c98723d2a1b3f6f0874bcc4140cb2931dfd7e3c0b58ec07dcf326ad4931723ec24ddd16eab126a2

  • SSDEEP

    12288:RpHhez1LfTyHApKS+04Hy+BNjnjyZJ859lA:Rxhez1LjpKCXZe59

Malware Config

Targets

    • Target

      1b095ac58a05fa9b8bc145600d31a39d_JaffaCakes118

    • Size

      432KB

    • MD5

      1b095ac58a05fa9b8bc145600d31a39d

    • SHA1

      a42ef0dcd3652df620d04428c319e173b99ee61f

    • SHA256

      c05e660e8265aea306ad08f3b1d5909fd80418750c9bd7cf1fba9f7b5b4d9141

    • SHA512

      a6092b8280e5cae2902d718b03bb7f05d8f1e349f18560e76c98723d2a1b3f6f0874bcc4140cb2931dfd7e3c0b58ec07dcf326ad4931723ec24ddd16eab126a2

    • SSDEEP

      12288:RpHhez1LfTyHApKS+04Hy+BNjnjyZJ859lA:Rxhez1LjpKCXZe59

    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

1
T1005

Email Collection

1
T1114

Tasks