HALFBAKED
Description
(FireEye) The HALFBAKED malware family consists of multiple components designed to establish and maintain a foothold in victim networks, with the ultimate goal of gaining access to sensitive financial information. This version of HALFBAKED connects to the following C2 server:
hxxp://198[.]100.119.6:80/cd hxxp://198[.]100.119.6:443/cd hxxp://198[.]100.119.6:8080/cd
This version of HALFBAKED listens for the following commands from the C2 server:
• info: Sends victim machine information (OS, Processor, BIOS and running processes) using WMI queries • processList: Send list of process running • screenshot: Takes screen shot of victim machine (using 58d2a83f777688.78384945.ps1) • runvbs: Executes a VB script • runexe: Executes EXE file • runps1: Executes PowerShell script • delete: Delete the specified file • update: Update the specified file
Names
Name |
---|
HALFBAKED |
VB Flash |
Category
Malware
Type
- Reconnaissance
- Backdoor
- Info stealer
Information
Mitre Attack
Malpedia
Alienvault Otx
Other Information
Uuid
7c520285-abe4-4a29-afc3-47ae713edd82
Last Card Change
2020-04-23