General

  • Target

    1bb6652f234f667a66f942bb5a891235_JaffaCakes118

  • Size

    211KB

  • Sample

    240701-r63edaxcpd

  • MD5

    1bb6652f234f667a66f942bb5a891235

  • SHA1

    1fe086405358e7e33a53587517d2bda188ba837f

  • SHA256

    8ebcfe4fde62b7248e47bc1b274cb3978dc7e10eb56553b7baf03bd1cabdb17f

  • SHA512

    9efc9b64ae865cee97f5ff14d3a18fda029c477b7ab1bc89851f34a7bf2c1f0ba299e1ad21f0984f09a162ce7f619b0151d464e7e93cc73e7c605a778c9c8821

  • SSDEEP

    6144:gWpOpiSbXho7Ke0PksCao97l0b9ZU2EzlW8:DWiCXh4KPPksCt95A9ZGW

Malware Config

Targets

    • Target

      1bb6652f234f667a66f942bb5a891235_JaffaCakes118

    • Size

      211KB

    • MD5

      1bb6652f234f667a66f942bb5a891235

    • SHA1

      1fe086405358e7e33a53587517d2bda188ba837f

    • SHA256

      8ebcfe4fde62b7248e47bc1b274cb3978dc7e10eb56553b7baf03bd1cabdb17f

    • SHA512

      9efc9b64ae865cee97f5ff14d3a18fda029c477b7ab1bc89851f34a7bf2c1f0ba299e1ad21f0984f09a162ce7f619b0151d464e7e93cc73e7c605a778c9c8821

    • SSDEEP

      6144:gWpOpiSbXho7Ke0PksCao97l0b9ZU2EzlW8:DWiCXh4KPPksCt95A9ZGW

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

1
T1005

Email Collection

1
T1114

Tasks