HALFBAKED

Description

(FireEye) The HALFBAKED malware family consists of multiple components designed to establish and maintain a foothold in victim networks, with the ultimate goal of gaining access to sensitive financial information. This version of HALFBAKED connects to the following C2 server:

hxxp://198[.]100.119.6:80/cd hxxp://198[.]100.119.6:443/cd hxxp://198[.]100.119.6:8080/cd

This version of HALFBAKED listens for the following commands from the C2 server:

• info: Sends victim machine information (OS, Processor, BIOS and running processes) using WMI queries • processList: Send list of process running • screenshot: Takes screen shot of victim machine (using 58d2a83f777688.78384945.ps1) • runvbs: Executes a VB script • runexe: Executes EXE file • runps1: Executes PowerShell script • delete: Delete the specified file • update: Update the specified file

Names

Name
HALFBAKED
VB Flash

Category

Malware

Type

  • Reconnaissance
  • Backdoor
  • Info stealer

Information

Mitre Attack

Malpedia

Alienvault Otx

Other Information

Uuid

7c520285-abe4-4a29-afc3-47ae713edd82

Last Card Change

2020-04-23