General

  • Target

    1e964f9251bfbdd2ab842ab1df72e12d_JaffaCakes118

  • Size

    410KB

  • Sample

    240702-j2xdkaxdnq

  • MD5

    1e964f9251bfbdd2ab842ab1df72e12d

  • SHA1

    28a30e3032cc5b23e130b6bb861c6f53fd09797d

  • SHA256

    d68423b7ee1aaca6f03ef4474885badfefef711697a39d4a749e1f26b0ff2868

  • SHA512

    5757ce4c5d267486018a300b205a95ade8b6565b8ebc25923d01ac562cf42f26794a29ea3c903941edab15fd3e8cc1baecf573cee764cc8abe143baedc4eba35

  • SSDEEP

    6144:k9+JPqCBIIIckOTFMYZy9Y/nYn7ZbXmXrpcBW5DTL4DO1iOXvENfme:AIIc7hMYZy9YPY7ZLmXaCL4DORcN+e

Malware Config

Targets

    • Target

      1e964f9251bfbdd2ab842ab1df72e12d_JaffaCakes118

    • Size

      410KB

    • MD5

      1e964f9251bfbdd2ab842ab1df72e12d

    • SHA1

      28a30e3032cc5b23e130b6bb861c6f53fd09797d

    • SHA256

      d68423b7ee1aaca6f03ef4474885badfefef711697a39d4a749e1f26b0ff2868

    • SHA512

      5757ce4c5d267486018a300b205a95ade8b6565b8ebc25923d01ac562cf42f26794a29ea3c903941edab15fd3e8cc1baecf573cee764cc8abe143baedc4eba35

    • SSDEEP

      6144:k9+JPqCBIIIckOTFMYZy9Y/nYn7ZbXmXrpcBW5DTL4DO1iOXvENfme:AIIc7hMYZy9YPY7ZLmXaCL4DORcN+e

    • Detect Neshta payload

    • Neshta

      Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Modifies system executable filetype association

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Privilege Escalation

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks