General

  • Target

    JaffaCakes118_1271919ae14d9d651f39b99954913efc

  • Size

    1.2MB

  • Sample

    250614-xxakwstks5

  • MD5

    1271919ae14d9d651f39b99954913efc

  • SHA1

    71aba078ab4b5d0cc069240c9a8f9ece632b0c82

  • SHA256

    b99cba07cd51b158075a1fcc8371d06b8d2bb20850ace051d0b96d823bc06d9a

  • SHA512

    0da2acbfed54b51641d888bc5c44f0d89f89f615c49c4bddce7407e05e15216f0597351a8efe22dc795af602fd2c693acb3a67636670dbca83f3569aec63d2e9

  • SSDEEP

    24576:FCp0jfOFqaNyFF98tHhVQoah8UlvyzRuYxJrSUYIDx4hZ9BaMFBA:FOkWFDKMhVxU4FuYxJGU5DxWZ3a5

Malware Config

Extracted

Family

redline

Botnet

800bot

C2

193.0.61.155:10790

Targets

    • Target

      JaffaCakes118_1271919ae14d9d651f39b99954913efc

    • Size

      1.2MB

    • MD5

      1271919ae14d9d651f39b99954913efc

    • SHA1

      71aba078ab4b5d0cc069240c9a8f9ece632b0c82

    • SHA256

      b99cba07cd51b158075a1fcc8371d06b8d2bb20850ace051d0b96d823bc06d9a

    • SHA512

      0da2acbfed54b51641d888bc5c44f0d89f89f615c49c4bddce7407e05e15216f0597351a8efe22dc795af602fd2c693acb3a67636670dbca83f3569aec63d2e9

    • SSDEEP

      24576:FCp0jfOFqaNyFF98tHhVQoah8UlvyzRuYxJrSUYIDx4hZ9BaMFBA:FOkWFDKMhVxU4FuYxJGU5DxWZ3a5

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Redline family

    • SectopRAT

      SectopRAT is a remote access trojan first seen in November 2019.

    • SectopRAT payload

    • Sectoprat family

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Executes dropped EXE

    • Suspicious use of SetThreadContext

MITRE ATT&CK Enterprise v16

Tasks