General

  • Target

    22da700b79646f8f588060342d279580_JaffaCakes118

  • Size

    40KB

  • Sample

    240703-sxe36awdlf

  • MD5

    22da700b79646f8f588060342d279580

  • SHA1

    a64fde231996714d570fd04c05c806723987a864

  • SHA256

    ab7a1b3fa3872430bbf831cd59744b91ba0a09403320a5cfd375dd01c2ea885c

  • SHA512

    79f2cb1adde33e9ba9ee92a4f12ad6df593a78c43131b07c7a4016019eb0056a115acee735998aeaa243b05b9ba40fb658ffce46a61d9ba0494217cdac957797

  • SSDEEP

    768:nyxqjQl/EMQt4Oei7RwsHxKANM0nDhlzOQdJ:yxqjQ+P04wsZLnDrC

Malware Config

Targets

    • Target

      22da700b79646f8f588060342d279580_JaffaCakes118

    • Size

      40KB

    • MD5

      22da700b79646f8f588060342d279580

    • SHA1

      a64fde231996714d570fd04c05c806723987a864

    • SHA256

      ab7a1b3fa3872430bbf831cd59744b91ba0a09403320a5cfd375dd01c2ea885c

    • SHA512

      79f2cb1adde33e9ba9ee92a4f12ad6df593a78c43131b07c7a4016019eb0056a115acee735998aeaa243b05b9ba40fb658ffce46a61d9ba0494217cdac957797

    • SSDEEP

      768:nyxqjQl/EMQt4Oei7RwsHxKANM0nDhlzOQdJ:yxqjQ+P04wsZLnDrC

    • Neshta

      Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.

    • Loads dropped DLL

    • Modifies system executable filetype association

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Privilege Escalation

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks