General

  • Target

    1c03370879d24cab66d2fbbe633e3576_JaffaCakes118

  • Size

    30KB

  • Sample

    240701-wvw6fawcjj

  • MD5

    1c03370879d24cab66d2fbbe633e3576

  • SHA1

    baf8aa820806f5987860ff65735f655667dc919c

  • SHA256

    b08a1fc1c0016ca5ad2be6257cdc7a344abb1bce4c6f41c8da8a7a46dee25909

  • SHA512

    48548d1842adea64dc1949f1bf5b73b6b221fca92076f95916ba1968fa1f7e50002cd4f519812f988b6622b867cfd250d88787b7d9ea04eb933f9253a481ad68

  • SSDEEP

    768:o8GTKIJ9bIxOo3K/9wkrKGz2FpeBHiJJ7Ta:ofTf9sxOo6CkrKGqikDC

Malware Config

Targets

    • Target

      1c03370879d24cab66d2fbbe633e3576_JaffaCakes118

    • Size

      30KB

    • MD5

      1c03370879d24cab66d2fbbe633e3576

    • SHA1

      baf8aa820806f5987860ff65735f655667dc919c

    • SHA256

      b08a1fc1c0016ca5ad2be6257cdc7a344abb1bce4c6f41c8da8a7a46dee25909

    • SHA512

      48548d1842adea64dc1949f1bf5b73b6b221fca92076f95916ba1968fa1f7e50002cd4f519812f988b6622b867cfd250d88787b7d9ea04eb933f9253a481ad68

    • SSDEEP

      768:o8GTKIJ9bIxOo3K/9wkrKGz2FpeBHiJJ7Ta:ofTf9sxOo6CkrKGqikDC

    • Reads user/profile data of local email clients

      Email clients store some user data on disk where infostealers will often target it.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

2
T1005

Email Collection

1
T1114

Tasks