General

  • Target

    1ef7be727d7656f45d19cae632732fb4_JaffaCakes118

  • Size

    385KB

  • Sample

    240702-mew13a1hpm

  • MD5

    1ef7be727d7656f45d19cae632732fb4

  • SHA1

    26d61d189673722854181594594a74348eb3a952

  • SHA256

    948c1e7f771462f59f702de527e0ebf6c109bf9762284a9a54a91f08700d8404

  • SHA512

    0b933f2a1a53840fef5deb834e6c8c22853910e6503d9f7191a91a3ac05722a225d1d17684107d5c6615356ece425b57b3aa7898cd066556f667954713356227

  • SSDEEP

    6144:09BUwrQ9Ey4sxZZQttyCVxaWYSda4bHPS9x6qr6jDRPWHz6kp62kVCRjCK:GkEfeAtpVxag1bvgx6NdC62kVsjV

Malware Config

Targets

    • Target

      1ef7be727d7656f45d19cae632732fb4_JaffaCakes118

    • Size

      385KB

    • MD5

      1ef7be727d7656f45d19cae632732fb4

    • SHA1

      26d61d189673722854181594594a74348eb3a952

    • SHA256

      948c1e7f771462f59f702de527e0ebf6c109bf9762284a9a54a91f08700d8404

    • SHA512

      0b933f2a1a53840fef5deb834e6c8c22853910e6503d9f7191a91a3ac05722a225d1d17684107d5c6615356ece425b57b3aa7898cd066556f667954713356227

    • SSDEEP

      6144:09BUwrQ9Ey4sxZZQttyCVxaWYSda4bHPS9x6qr6jDRPWHz6kp62kVCRjCK:GkEfeAtpVxag1bvgx6NdC62kVsjV

    • Neshta

      Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Loads dropped DLL

    • Modifies system executable filetype association

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Privilege Escalation

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks