General

  • Target

    1ebeed6e2a584ace2893abd43451214b_JaffaCakes118

  • Size

    526KB

  • Sample

    240702-k3sx7svgrg

  • MD5

    1ebeed6e2a584ace2893abd43451214b

  • SHA1

    26f60c853e7adf7444b4611aa4b56ecceb626fb9

  • SHA256

    4971e09f5bfb7a1de4ae72067c47d1252338592c59067ca750ce2ae1c7d965b7

  • SHA512

    0bc8db29757e88f25e67e29b38bf271eeab11bcc504f51efeb674aa640222c85dee1f41e20b7418be39936d27521ebbc7f56f427ac7f38b2a4d711e02c8f001e

  • SSDEEP

    12288:Jgt/ldfz/hvVcWdaUSLYr55h/TO8aZkIBQh+B0:JGn/hvtvVO8wkImkB0

Malware Config

Targets

    • Target

      1ebeed6e2a584ace2893abd43451214b_JaffaCakes118

    • Size

      526KB

    • MD5

      1ebeed6e2a584ace2893abd43451214b

    • SHA1

      26f60c853e7adf7444b4611aa4b56ecceb626fb9

    • SHA256

      4971e09f5bfb7a1de4ae72067c47d1252338592c59067ca750ce2ae1c7d965b7

    • SHA512

      0bc8db29757e88f25e67e29b38bf271eeab11bcc504f51efeb674aa640222c85dee1f41e20b7418be39936d27521ebbc7f56f427ac7f38b2a4d711e02c8f001e

    • SSDEEP

      12288:Jgt/ldfz/hvVcWdaUSLYr55h/TO8aZkIBQh+B0:JGn/hvtvVO8wkImkB0

    • Detect Neshta payload

    • Neshta

      Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Modifies system executable filetype association

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Privilege Escalation

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks