General

  • Target

    1dcad7c8f56207b2c423353f0c328755_JaffaCakes118

  • Size

    452KB

  • Sample

    240702-22vh3svbkg

  • MD5

    1dcad7c8f56207b2c423353f0c328755

  • SHA1

    d7e3924ca83e1a2355f3f1e2816dfd417892afc2

  • SHA256

    4e6531aa7f8fdb4c21f0559b2b7951afbc2624e9a69a0588c1633508a173ab38

  • SHA512

    af0deb1fd5cbbf2a925143d87b9d3acb7feec6735ec13d6d7be812af9268419d02080318ed1f48a4ad8f301c8f8f82496426abe2698c7dba3bff6fe248afc285

  • SSDEEP

    6144:7btQmb25Zh18hqJbDqSB7Lvq2XsjYiVmOf7Yp4jOa9UpE:7mmCVRtPvq2+d/

Score
10/10

Malware Config

Extracted

Family

gozi

Targets

    • Target

      1dcad7c8f56207b2c423353f0c328755_JaffaCakes118

    • Size

      452KB

    • MD5

      1dcad7c8f56207b2c423353f0c328755

    • SHA1

      d7e3924ca83e1a2355f3f1e2816dfd417892afc2

    • SHA256

      4e6531aa7f8fdb4c21f0559b2b7951afbc2624e9a69a0588c1633508a173ab38

    • SHA512

      af0deb1fd5cbbf2a925143d87b9d3acb7feec6735ec13d6d7be812af9268419d02080318ed1f48a4ad8f301c8f8f82496426abe2698c7dba3bff6fe248afc285

    • SSDEEP

      6144:7btQmb25Zh18hqJbDqSB7Lvq2XsjYiVmOf7Yp4jOa9UpE:7mmCVRtPvq2+d/

    Score
    8/10
    • Server Software Component: Terminal Services DLL

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks